Security & Data Protection

Last updated: August 11, 2026

Our approach

The Growth Syndicate B.V. (TGS) works with B2B companies across marketing, growth, RevOps, analytics, content, design and web development. That work can involve access to client systems, business contact data, campaign information and confidential commercial information.

We use a documented security and data-protection framework designed around least-privilege access, secure devices, strong authentication, controlled use of third-party tools, data minimisation and clear incident-response responsibilities. Where a client has stricter contractual or security requirements, those requirements take precedence for that engagement.

Security practices at a glance

Control area What we do
Access control Access is granted only to people who need it for their assigned client work, and is removed when no longer required.
Authentication Individual accounts are used wherever possible, with multi-factor authentication on relevant business and client systems where supported.
Devices Client work is performed on TGS-issued or otherwise approved devices configured with full-disk encryption, automatic locking, endpoint protection and security updates.
Credentials Passwords and shared credentials are stored and shared through TGS-managed 1Password rather than ordinary email, Slack or WhatsApp.
Client separation Client information is logically separated through client-specific folders, channels, workspaces and/or client-owned systems.
Data minimisation Client Personal Data stays in client-controlled or TGS-approved cloud systems wherever possible. Temporary local copies are tightly limited and deleted when no longer needed.
AI & automation General-purpose AI tools may not receive raw CRM exports, contact lists, authentication credentials or production data unless a specifically approved client use case permits it.
Incidents Suspected security or privacy incidents must be escalated internally immediately and, in any event, within four hours of awareness.

Identity and access management

Access to client information is based on role, assignment and business need. TGS uses individual company identities and client-specific invitations wherever possible. Shared or generic logins are treated as exceptions and are used only where a client or tool setup requires them, with credentials handled through approved password-management controls.

Access is periodically reviewed and is removed when a person leaves TGS, changes role, is removed from a client engagement or otherwise no longer needs the access.

Device and endpoint security

Personnel handling client information use TGS-issued or approved work devices. TGS-issued MacBooks are configured with full-disk encryption, password and/or biometric authentication, automatic screen locking, endpoint protection and operating-system/security updates.

Physical access to work devices is restricted to the authorised user, and company devices are returned as part of offboarding.

Credential protection

TGS uses 1Password for company-managed credential storage and authorised sharing. Credentials should not be intentionally sent through ordinary email, Slack, WhatsApp or unsecured documents, and company or client credentials must not be reused for personal services.

Client data separation and handling

Client data is separated from other client and internal information using dedicated folders, channels, workspaces and/or client-controlled systems. Access is limited to the team members assigned to that client.

We work in client systems directly wherever practical. Exports of CRM data, contact databases or similar Personal Data are limited to cases where they are necessary and authorised. Where a temporary local copy is genuinely required, it must be stored only on an encrypted approved device, deleted as soon as it is no longer needed and, as a TGS baseline, no later than 30 days unless another period has been expressly authorised.

AI and automation

TGS uses AI and automation tools in parts of its work, but their use is subject to data-protection and client-specific restrictions. We aim to remove, anonymise or minimise Personal Data before using AI where reasonably possible.

  • Raw CRM exports and contact lists are not uploaded to unapproved general-purpose AI systems.
  • Authentication credentials are never submitted to AI or automation tools.
  • Production-system data is not submitted unless the use case has been specifically authorised.
  • Client-specific restrictions on AI always override TGS's general tool policy.

Personnel, confidentiality and security responsibilities

People who handle client data are subject to confidentiality and data-protection obligations appropriate to their role. They receive TGS security and data-handling requirements at onboarding and are required to acknowledge the applicable rules. Relevant personnel reconfirm key security obligations periodically.

Sub-processors and third-party services

TGS uses third-party cloud, collaboration, marketing, analytics and productivity services to deliver its work. Where a provider or contractor processes client Personal Data on our behalf, TGS applies the contractual and approval requirements applicable to the client engagement.

We do not treat the existence of a TGS account as blanket permission to use a tool for every client. Client-approved tools, system restrictions and data-processing terms are applied where required.

International data transfers

TGS works with an international team. Where access to EEA Personal Data from outside the EEA constitutes a restricted international transfer, TGS uses an appropriate GDPR transfer mechanism. Depending on the circumstances, this may include the European Commission's Standard Contractual Clauses together with supporting transfer assessments and supplementary safeguards.

Client-specific country restrictions or prior-approval requirements are respected and take precedence over the TGS baseline.

Security incidents

TGS maintains a documented incident-escalation process. Personnel must report an actual or suspected security or privacy incident immediately and, in any event, within four hours of becoming aware of it. TGS then assesses, contains and investigates the incident and follows the notification and cooperation requirements in the applicable client agreement and data-protection law.

Offboarding and access removal

When a person leaves TGS or is removed from an engagement, relevant company and client-system access is revoked, company credentials and password-manager access are removed as applicable, the company device is returned, and authorised temporary local client data is deleted or returned in accordance with instructions.

Audit and client assurance

TGS maintains internal documentation to evidence the controls relevant to client Data Processing Agreements and security reviews. Depending on the engagement and the scope of a review, this may include our information-security policy, security self-attestation, data-processing and confidentiality terms, access records, international-transfer documentation and other relevant evidence.

Detailed internal security documents are not published publicly, but appropriate information can be made available to clients during procurement, contracting or a contractual audit, subject to confidentiality and data-minimisation considerations.

Data protection

When TGS processes Personal Data on behalf of a client, we act under the applicable client agreement and Data Processing Agreement. We process client Personal Data only for authorised service purposes and do not reuse it for unrelated purposes or cross-client datasets unless expressly authorised.

For information about how TGS processes Personal Data for its own purposes - for example through our website or business communications - please see our Privacy Policy.

Security and privacy questions

For security, privacy or data-protection enquiries, contact legal@thegrowthsyndicate.com.

The Growth Syndicate B.V.
Jozef Israëlskade 46-1
1072 SB Amsterdam
The Netherlands

Let's get started building your B2B growth engine!

Book a session with us