Privacy policy
What I do with your data, and how you stop it.
I run Throughline myself, so this page was written by the person who actually holds your data, not by a template. It says what I collect, why, who sees it, how long I keep it, and the one reply that ends all contact. Plain English, about three minutes.
Who I am
Throughline is the trading name of Tobias van den Broek, a sole trader (eenmanszaak) registered in the Netherlands, Chamber of Commerce (KVK) number 42110749. I am the data controller for everything on this page, and the person who answers when you write.
- Address
- Van Hogendorplaan 1e, Hilversum, Netherlands
- Privacy questions and requests
- hello@throughlinegrowthsystem.com, or reply to any email I have sent you
I am a Dutch controller who contacts UK businesses, so this page is written to meet both the EU GDPR and the UK GDPR, together with PECR, the UK’s rules on electronic marketing.
The short version
- If I emailed you first, your work contact details came from a business contact database or your company’s own public website. I write to a small number of businesses I think I can help, and I stop the moment you reply.
- Opting out is one reply. Reply STOP to any email and your address goes on a permanent suppression list. That list is the one thing I keep forever, so “never again” holds.
- This site sets no cookies today. No analytics, no advertising pixels. When that changes (planned for mid-September 2026), a consent banner comes first and nothing loads until you say yes.
- The fit check and any call are used for one thing: judging whether we are a fit and replying to you. Calls may be recorded, and we say so at the start.
- Nothing is sold or shared for anyone else’s marketing. Client contact lists stay in the client’s own systems. I never take copies.
What I process and where it comes from
Five things happen with personal data here. For each: what I hold, and where it came from.
Cold outreach, if I emailed you first
What I hold. Your name, role and work email address, and your company’s name, website, size and sector.
Where it came from. Business contact databases, your company’s own public website, public professional profiles, and public company registers.
Why you are reading this. I did not get this data from you, so the law (GDPR Article 14) says I must tell you what I hold, where it came from, why, and what your rights are. This page is that notice, and the first email you receive links to it.
Visiting this website
What I hold. Nothing personal from me. The host, Netlify, keeps standard server logs (IP address, browser type, pages requested, times) to run and secure the site. Fonts are served from this site itself, so no font network sees you.
Cookies. None today. No analytics, no advertising pixels. Section 05 covers what changes in September and how consent will work.
The fit check
What I hold. What you type into the fit check: your name, work email, phone number, company website and your answers to the questions. Alongside it, the page that referred you, any campaign tags in the link you arrived on, and the time you submitted.
Where it came from. You, and only when you press submit. Nothing is captured before that.
Assessment and strategy calls
What I hold. Your name and contact details, what we discuss, and the notes taken. Calls are taken by me or by Emil Turda, the growth advisor named on the About page. They may be recorded and transcribed so we can listen instead of typing. We say so at the start of the call; tell us and we will not record.
Where it came from. You, on the call.
Opt-outs: the suppression list
What I hold. Your email address (sometimes your company’s domain) and a note of when you opted out. Nothing else.
Why I keep it. I check it before I write to anyone. It is how the opt-out works. Section 08 explains why it is never deleted.
Client data during an engagement
Governed by our agreement, not this page. One standing promise is repeated here because it matters: your contact lists stay in your own systems. I work inside them and never take copies.
Why, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Introducing Throughline to UK businesses by email | Outreach contact data (section 03) | Legitimate interests, Art. 6(1)(f) |
| Judging whether we are a fit and replying to you | Fit check answers, call notes, recordings | Steps at your request before a contract, Art. 6(1)(b); legitimate interests where no contract follows |
| Running and securing this website | Server logs kept by the host | Legitimate interests, Art. 6(1)(f) |
| Making sure I never contact you again after you opt out | The suppression list | Legal obligation, Art. 6(1)(c), and legitimate interests |
| Advertising measurement on this site (from mid-September 2026) | Cookie and pixel data | Consent, Art. 6(1)(a), given in the banner |
My legitimate interest is plain: I am a small business finding clients by contacting other businesses. I judged it proportionate because I use business contact details in a business context only, keep it to a few short emails, stop when you reply, make opting out a single reply, and honour every opt-out permanently. A written assessment of this exists. Ask and I will send it.
Article numbers refer to the GDPR; the UK GDPR uses the same numbering. Under PECR, emails to business contacts follow the corporate-subscriber route: no prior consent, an easy way to say no, always honoured.
International transfers
Some of these providers are based in the United States, so personal data can leave the EU and the UK. Where a provider is certified under the EU-US Data Privacy Framework (and its UK Extension), I rely on that. Otherwise the transfer rests on the Standard Contractual Clauses in the provider’s data processing agreement, with the UK Addendum where UK data is involved.
Ask and I will tell you which safeguard applies to a given provider and point you to the relevant clauses.
How long I keep data
- Outreach contact data. Deleted, or reduced to a suppression entry, within 12 months of my last contact with you. Sooner the moment you object.
- Fit check submissions. 12 months after our last contact, unless we start working together. Then the agreement’s terms apply.
- Call recordings and transcripts. 12 months after the call, unless we start working together. Deleted sooner on request.
- Server logs. Kept briefly by the host under its own schedule. I do not export or analyse them.
- The suppression list. Indefinitely, by design. Deleting your address from it is what would let a data provider put you back on a list. Keeping that one entry is what makes “never again” true.
Where a legal duty requires a longer period (for example accounting records once we work together), that period applies instead.
Your rights
Under the GDPR and the UK GDPR you have these rights over your data. To use any of them, email hello@throughlinegrowthsystem.com or reply to any email I have sent. I answer within one month, and I may need to check the request really comes from you. There is no charge.
- Access. Ask what I hold about you and get a copy.
- Rectification. Have anything wrong corrected.
- Erasure. Have it deleted. For outreach data this is done as permanent suppression.
- Restriction. Ask me to hold the data but stop using it.
- Portability. Get the data you gave me in a machine-readable file.
- Objection. Object to any processing based on legitimate interests. For direct marketing this is absolute: see below.
- Withdraw consent. Where consent is the basis (cookies, call recording), withdraw it at any time.
You can stop me contacting you at any time, for any reason or none. Reply STOP to any email I send, or write to hello@throughlinegrowthsystem.com. That is the whole process: no form, no login, no confirmation step. Your address goes on the suppression list and I never contact it again.
Complaints
If you think I have handled your data wrongly, I would rather hear it from you first, and I will put it right. You also have the right to complain to a supervisory authority at any time:
- Autoriteit Persoonsgegevens The Dutch data protection authority. I am a Dutch controller, so this is my lead authority.
- Information Commissioner’s Office The UK regulator. If you are in the UK you can complain here directly.
Changes to this page
When something changes, this page changes first, and the date at the top moves. If a change matters to you (a new purpose, a new kind of data, a new tool that sees it), it will be described here before it happens, not after.