T2D3 OS
HomeFor CMOsCost & ROIPricingBlog
Sign inStart free
T2D3 OS

The B2B SaaS go-to-market method, running as software.

hello@t2d3.club
Product
  • All features
  • GTM Foundation
  • T2D3 Playbook
  • Content Studio
  • Website & GEO
  • AI Engine
Platform
  • Command Center
  • Relay
  • Team & Talent
  • Agency Workspace
  • Expert Marketplace
  • The Living GTM
  • Haul to Lode — humans are the loop
  • Work on the marketplace
  • Pricing
Library
  • Beyond templates
  • What T2D3 OS is not
  • Learn (blog)
  • Wren's journal
  • Changelog
  • Templates & playbooks
  • Ready-to-run playbooks
  • Masterclass
  • Certification
  • Glossary
  • The playbook
  • Books by Stijn
  • Podcast
  • Newsletter
Free tools
  • Brand Voice lab
  • GTM diagnostic
  • Growth labor calculator
  • Cost calculator
  • ROI calculator
Company
  • About
  • The team
  • Coaching
  • For fractional CMOs
  • Founding cohort
  • Join the journey
  • FAQ
  • Support
© 2026 T2D3. Triple twice, double three times.
PrivacyTermsTrust
T2D3 Operating SystemT2D3 Operating SystemSign in →

Trust & Compliance

Last updated: October 4, 2026

This page is for the security, legal and procurement teams reviewing T2D3 Inc. ("T2D3") and the T2D3 Operating System (the "Service"). It gathers what a vendor review usually asks for in one place and links to the binding text in our Privacy Policy and Terms of Service.

At a glance

  • Data Processing Agreement — available to every business customer, with the EU Standard Contractual Clauses and the UK Addendum.
  • Sub-processors — every provider named, with at least 30 days' notice before a new one is added.
  • Breach notification — affected customers and supervisory authorities, within 72 hours where GDPR requires it.
  • AI training — your prompts and outputs are never used to train our models or our providers' models.
  • Certifications — no SOC 2 report or ISO/IEC 27001 certificate yet; we say so plainly below.

1. Data Processing Agreement (DPA)

Where T2D3 processes personal data on your behalf, we act as your processor and you remain the controller. We sign a Data Processing Agreement with business customers who need one, covering the terms GDPR Article 28 requires: processing only on your documented instructions, confidentiality of personnel, security measures, sub-processor flow-down and notice, assistance with data-subject requests, breach notification, deletion or return of data at the end of the engagement, and audit cooperation.

For transfers from the European Economic Area, the United Kingdom and Switzerland, the DPA incorporates the European Commission's Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum, as described in Section 7 of our Privacy Policy.

To request a DPA for signature, email privacy@t2d3.club with your company's legal name, registered address and the name of the person who will sign.

2. Sub-processors

The current list of sub-processors — who each one is and what it does for the Service — is maintained in Section 4 of our Privacy Policy. Each is bound by a data processing agreement and processes personal data only to perform its function.

We give at least 30 days' advance notice of a new or replacement sub-processor by email or in-app notification, so you can raise an objection before the change takes effect.

3. Security controls

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256).
  • Row-level security enforced in the database, so one organization's records cannot be read through another's session.
  • Role-based access and least privilege for our own team, with multi-factor authentication on all administrative and production access.
  • Regular security reviews and dependency scanning.
  • Logging and monitoring of access to production systems.

The full statement is in Section 10 of our Privacy Policy. We complete security questionnaires on request — send yours to privacy@t2d3.club.

4. Certifications (SOC 2, ISO/IEC 27001)

T2D3 does not currently hold a SOC 2 report or an ISO/IEC 27001 certificate. We would rather tell you that here than have it surface at the end of a review. When an audit is under way we will name the auditor and the expected report date on this page.

Our hosting, database and payment providers publish their own independent security attestations; we can point you to the ones relevant to your review on request.

5. AI processing and the EU AI Act

The Service uses general-purpose AI models from third-party providers to draft and analyze business-to-business marketing work: positioning, personas, content and planning. It is not designed or offered for the high-risk purposes listed in Annex III of the EU AI Act (for example employment decisions about individuals, credit scoring or access to essential services), and it performs none of the practices the Act prohibits.

How we meet the obligations that do apply to us as a deployer of AI:

  • Transparency. AI output is presented as a draft, and where it is grounded in your own material the product shows the sources it drew on.
  • Human oversight. AI output is a draft for people in your team to review, edit and approve; the product's lock step records that a person accepted it.
  • No training on your data. Prompts and outputs are not used to train our models or our providers' models. Providers may keep them for up to 30 days for abuse monitoring; zero-retention arrangements are available on our top-tier plans where the provider supports them. See Section 3 of our Privacy Policy.

This describes how we have assessed the Service under the Act; it is not legal advice for your own obligations.

6. Incident response

If a personal data breach affects your data, we notify you and the relevant supervisory authorities in accordance with applicable law, including within 72 hours where GDPR requires it. The notice describes what happened, the data involved, the likely consequences and the measures taken.

To report a suspected vulnerability or incident, email privacy@t2d3.club.

7. Your data at the end of an engagement

  • Return. Before deletion, you can ask for a copy of your organization's data in a structured, machine-readable format.
  • Deletion. We delete or anonymize account data and content within 30 days of a deletion request, except records the law requires us to keep (for example tax records for 7 years).
  • Backups. Deleted data can remain in encrypted backups for up to 90 days, until normal backup rotation purges it.
  • AI providers. Provider-side copies follow the retention described in Section 5 above.

Retention by data category is set out in Section 5 of our Privacy Policy; how to request deletion is on our Delete your account page.

8. Audit logging

Workspace audit logs record administrative and data-handling actions (who did what, and when) for your organization's administrators. Audit logging is deliberately non-blocking: if an entry cannot be written, the action still completes rather than failing. The audit log is therefore a best-effort accountability record, not a guaranteed-complete ledger. Infrastructure-level logging of production systems runs independently of it. See Section 10 of our Privacy Policy.

9. Contact

For DPA requests, security questionnaires and data-protection questions:

T2D3 Inc.
Attn: Privacy
7300 State Highway 121, Suite 300
McKinney, TX 75070
United States of America

Email: privacy@t2d3.club

© 2026 T2D3 Inc.. All rights reserved. · Privacy Policy · Terms of Service