Last updated: June 23, 2026
This Data Processing Addendum ("DPA") supplements, and is incorporated by reference into, the Terms of Service (the "Agreement") between Sutra Spaces LLC, a Delaware limited liability company with its principal place of business at 27 Joshua Edwards Court, East Hampton, NY 11937 ("Sutra" or "Processor"), and the customer that has entered into the Agreement (the "Customer" or "Controller").
By accepting the Agreement or by using the Services, Customer accepts this DPA and authorizes Sutra to process Customer Personal Data in accordance with its terms.
In the event of any conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA prevails. If a Customer requires a wet-signed copy of this DPA, please contact support@sutra.co.
1. Definitions
GDPR means Regulation (EU) 2016/679 (the General Data Protection Regulation), and, where applicable, the UK General Data Protection Regulation as incorporated into UK law by the European Union (Withdrawal) Act 2018 and supplemented by the Data Protection Act 2018 (the "UK GDPR"), and the Swiss Federal Act on Data Protection ("FADP").
Data Protection Laws means the GDPR and any other applicable laws and regulations relating to the processing of Personal Data and privacy that apply to a Party in its performance under this DPA.
Personal Data, Processing, Controller, Processor, Sub-processor, Data Subject, Special Categories of Personal Data, Personal Data Breach, and Supervisory Authority have the meanings given in the GDPR.
Customer Personal Data means Personal Data Processed by Sutra on behalf of Customer in connection with the Services, as further described in Annex 1.
Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of Personal Data to third countries pursuant to the GDPR, set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.
UK Addendum means the International Data Transfer Addendum to the EU Commission SCCs issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018, version B1.0 (or any successor version).
2. Scope, Roles and Instructions
2.1 Roles.
Processor role. With respect to the Processing of Customer Personal Data — that is, Personal Data Processed by Sutra on Customer's behalf in connection with the provision of the Services — Customer is the Controller, Sutra is the Processor, and Sutra may engage Sub-processors in accordance with Section 5. This DPA governs that Processing.
Independent Controller role. Sutra also acts as an independent Controller in respect of certain limited categories of personal data it collects directly from Customer's administrators and end users for Sutra's own purposes, including: (i) Customer administrator account, billing and contract-administration data; (ii) marketing communications data; and (iii) aggregated or pseudonymized usage, analytics, security, error and feedback data used to operate, secure, troubleshoot and improve the Services. Sutra's processing of personal data in its independent-Controller capacity is governed by Sutra's Privacy Policy rather than by this DPA.
2.2 Subject matter, duration, nature, purpose. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are described in Annex 1.
2.3 Documented instructions. Sutra shall Process Customer Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by Union or Member State law to which Sutra is subject; in such a case, Sutra shall inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
2.4 Customer instructions are constituted by (a) the Agreement, (b) this DPA, and (c) any further written instructions issued by Customer and acknowledged by Sutra. Sutra shall promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
2.5 Customer compliance. Customer is responsible for the lawfulness of the Processing of Customer Personal Data, including ensuring that it has obtained all necessary consents and notices required to enable Sutra to Process Customer Personal Data as contemplated by the Agreement and this DPA.
2.6 Prohibited Personal Data. Customer shall not upload, submit, transmit or otherwise cause to be Processed through the Services any of the following categories of personal data (collectively, "Prohibited Personal Data"):
- Special categories of Personal Data within the meaning of Article 9 GDPR (including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, and data concerning a person's sex life or sexual orientation), and personal data relating to criminal convictions and offences;
- Biometric identifiers or templates used for the purpose of uniquely identifying a natural person;
- Payment card data, payment authentication data, or any other cardholder data as defined under the Payment Card Industry Data Security Standard, except where Customer uses Sutra's standard integrated payment-processing functionality (which routes payment data to Sutra's payment-processor Sub-processor without Sutra storing it);
- Financial account information of the kind subject to the Gramm-Leach-Bliley Act;
- Government-issued identification numbers, including Social Security Numbers, Social Insurance Numbers, passport numbers and driver's license numbers;
- Personal data of any individual whom Customer knows to be under thirteen (13) years of age (or, in any jurisdiction that prescribes a higher minimum age for online services, that higher age), except where Customer has obtained verifiable parental consent in accordance with the Children's Online Privacy Protection Act (COPPA) or any equivalent applicable law and has separately notified Sutra in writing;
- Protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA), except under a separately negotiated written agreement (including, where required, a HIPAA Business Associate Agreement);
- Education records subject to the Family Educational Rights and Privacy Act (FERPA), except under a separately negotiated written agreement.
Customer is solely responsible for, and shall indemnify Sutra against, third-party claims arising from Customer's submission of Prohibited Personal Data through the Services. Where Sutra becomes aware that Prohibited Personal Data has been submitted, Sutra may, on notice to Customer, suspend the affected Processing pending Customer's removal of the Prohibited Personal Data or the Parties' execution of a written agreement permitting that Processing.
3. Confidentiality of Personnel
Sutra shall ensure that all personnel authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and have received appropriate training on their responsibilities in respect of Personal Data.
4. Security of Processing
4.1 Sutra shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, as relevant, the measures set out in Article 32(1) GDPR. A current description of such measures is set out in Annex 2 (the "Security Measures"). Sutra may update the Security Measures from time to time, provided that any such update does not materially diminish the overall level of protection.
4.2 In assessing the appropriate level of security, Sutra shall take account in particular of the risks that are presented by Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
5. Sub-processors
5.1 General authorization. Customer provides a general authorization for Sutra to engage Sub-processors to Process Customer Personal Data, subject to the requirements of this Section 5. The current list of Sub-processors is maintained at sutra.co/subprocessors (the "Sub-processor Page") and is incorporated into this DPA by reference. The Sub-processor Page constitutes the authoritative list of Sub-processors and the corresponding "Annex III" to the SCCs.
5.2 Notification mechanism. When Sutra adds or replaces a Sub-processor that Processes Customer Personal Data, Sutra will update the Sub-processor Page to reflect that change. Customer may subscribe at the Sub-processor Page to receive email notifications of such updates. Subscription to those notifications is the means by which Sutra communicates Sub-processor changes to Customer; Sutra has no obligation to notify non-subscribing customers individually, and Customer's sole responsibility for staying informed of Sub-processor changes is to subscribe or to review the Sub-processor Page periodically.
5.3 Affiliates. Sutra may engage its corporate affiliates as Sub-processors without separate notice, provided that any such affiliate is bound by data protection obligations no less protective than those set out in this DPA.
5.4 Objection and remedy. Customer may, within thirty (30) days following the publication of a Sub-processor addition or replacement on the Sub-processor Page, object to that change on legitimate, documented data protection grounds by written notice to Sutra. The Parties shall work together in good faith to address the objection. If they cannot resolve the objection within a reasonable period, Customer may, as its sole and exclusive remedy, terminate the affected Services on written notice to Sutra, with a pro-rata refund of any prepaid but unused fees for those Services from the effective date of termination. Customer's right to object under this Section 5.4 is its sole and exclusive remedy in respect of Sub-processor changes.
5.5 Flow-down. Sutra engages each Sub-processor on terms — whether by way of a standalone written agreement executed with the Sub-processor, by acceptance of the Sub-processor's standard terms of service incorporating a data processing addendum, or by other written legal act — that impose data protection obligations no less protective than those set out in this DPA and that provide sufficient guarantees to implement appropriate technical and organizational measures as required by Article 28(4) GDPR. Sutra remains fully liable to Customer for the performance of the Sub-processor's obligations to the extent set out in this DPA.
6. Data Subject Rights
Taking into account the nature of the Processing, Sutra shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer's obligation to respond to requests for exercising the Data Subject's rights laid down in Chapter III of the GDPR (including the rights of access, rectification, erasure, restriction, portability and objection). If Sutra receives a request from a Data Subject in respect of Customer Personal Data, Sutra shall promptly notify Customer and shall not respond to the request directly without Customer's prior written authorization, except as legally required.
7. Assistance with Controller Obligations
Taking into account the nature of the Processing and the information available to Sutra, Sutra shall assist Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR, including in relation to security of Processing, notification of Personal Data Breaches, communication of Personal Data Breaches to Data Subjects, data protection impact assessments, and prior consultation with Supervisory Authorities. Customer shall reimburse Sutra for any commercially reasonable costs incurred by Sutra in providing assistance that goes materially beyond the standard functionality of the Services.
8. Personal Data Breaches
8.1 Sutra shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Such notification shall, to the extent possible, include the information required under Article 33(3) GDPR; where the relevant information is not available at the time of the initial notification, Sutra shall provide it in subsequent communications as it becomes available.
8.2 Sutra shall take reasonable steps to contain and investigate any Personal Data Breach and to mitigate any adverse effects, and shall keep Customer informed of material developments.
9. International Transfers
9.1 Transfer mechanism. To the extent that Sutra's Processing of Customer Personal Data involves a transfer of Personal Data from the European Economic Area, the United Kingdom or Switzerland to a country that has not been the subject of an adequacy decision by the relevant authority, the Parties agree that such transfer shall be governed by the Standard Contractual Clauses, which are hereby incorporated by reference and deemed executed by the Parties, with the following selections:
- Module Two (Controller to Processor) applies where Customer is the Controller and Sutra is the Processor.
- Module Three (Processor to Processor) applies where Customer is itself a Processor and Sutra acts as Sub-processor.
- Clause 7 (Docking clause) shall apply.
- Clause 9 (Use of Sub-processors): Option 2 — General written authorization, with the notification mechanism set out in Section 5.2 of this DPA. The Parties agree that publication of changes on the Sub-processor Page satisfies the data importer's notification obligation under Clause 9(a), and that Customer's objection and termination right is as set out in Section 5.4.
- Clause 11 (Redress): the optional language is not included.
- Clause 17 (Governing law): the law of the Republic of Ireland, unless the law of another EU Member State allows for third-party beneficiary rights.
- Clause 18 (Choice of forum and jurisdiction): the courts of the Republic of Ireland.
- Annexes I, II and III to the SCCs are completed by reference to Annexes 1, 2 and 3 of this DPA (with the Sub-processor Page constituting Annex III).
9.2 UK transfers. Where Customer Personal Data is transferred from the UK, the UK Addendum applies, with Tables 1, 2 and 3 completed by reference to the SCCs and the Annexes of this DPA, and Table 4 indicating that neither Party may end the Addendum when it changes.
9.3 Swiss transfers. Where Customer Personal Data is subject to the FADP, the SCCs apply with the following modifications: references to the GDPR are deemed to include the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the term "Member State" shall not be interpreted so as to exclude Data Subjects in Switzerland from suing for their rights in their place of habitual residence.
9.4 EU-U.S. Data Privacy Framework. Where Sutra or a Sub-processor is certified under the EU-U.S. Data Privacy Framework (and, as applicable, the UK Extension and the Swiss-U.S. DPF), transfers to such entity may rely on that certification in lieu of the SCCs for so long as it remains in effect.
10. Audits and Records
10.1 Information. Sutra shall make available to Customer all information necessary to demonstrate compliance with Article 28 GDPR, including by providing copies of Sutra's then-current third-party audit reports, certifications and security documentation upon reasonable written request, subject to confidentiality obligations.
10.2 Audits. Where the information made available under Section 10.1 is not sufficient to demonstrate compliance, Customer may, on reasonable prior written notice (and no more than once in any twelve-month period unless required by a Supervisory Authority or following a Personal Data Breach), conduct an audit of Sutra's relevant Processing activities. Audits shall be conducted during regular business hours, in a manner that does not unreasonably interfere with Sutra's business operations, and subject to appropriate confidentiality undertakings. Customer shall bear its own costs and the reasonable costs of Sutra in supporting such audit.
11. Return or Deletion of Customer Personal Data
Upon termination or expiry of the Agreement, or earlier upon Customer's written request, Sutra shall, at Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless Union or Member State law requires storage of the Personal Data. Sutra may retain Customer Personal Data in accordance with its standard backup, archival and business continuity practices, provided such retained data remains subject to the protections of this DPA until deletion in the ordinary course of those practices.
12. Liability
Each Party's liability arising out of or in connection with this DPA, whether in contract, tort (including negligence) or otherwise, shall be subject to the limitations and exclusions of liability set forth in the Agreement. Nothing in this DPA limits any liability that cannot be limited under applicable law (including liability under Article 82 GDPR to the extent imposed by mandatory law).
13. Term and Termination
This DPA is effective when Customer accepts the Agreement or first uses the Services, and remains in force for as long as Sutra Processes Customer Personal Data on behalf of Customer under the Agreement. Sections that by their nature should survive termination shall so survive.
14. General
14.1 Order of precedence. Where this DPA conflicts with the Agreement on matters of data protection, this DPA prevails. The SCCs prevail over any conflicting terms of this DPA in respect of restricted transfers.
14.2 Severability. If any provision of this DPA is found by a court of competent jurisdiction to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
14.3 Governing law. Except as required by Section 9 in respect of restricted transfers, this DPA is governed by the governing law specified in the Agreement, or, if none, the laws of the State of Delaware.
14.4 Notices. Notices under this DPA to Sutra shall be sent to support@sutra.co. Notices to Customer shall be sent to the email address designated by Customer in the Agreement, or, if none, to the primary administrator email on Customer's account.
14.5 Updates. Sutra may update this DPA from time to time. Material changes will be communicated through the Services, by email to administrators, or by other reasonable means. The "Last updated" date at the top of this page indicates when this DPA was last revised. Continued use of the Services following the effective date of an update constitutes Customer's acceptance of the updated DPA.
Annex 1 — Description of the Processing
This annex completes Annex I to the EU SCCs (Module Two / Module Three) and the corresponding tables of the UK Addendum.
A. List of Parties
Data Exporter (Controller): The Customer, as identified in the Agreement. Role: Controller. Activities relevant to the data transferred: use of the Sutra platform to host learning and community spaces and manage member registrations.
Data Importer (Processor): Sutra Spaces LLC, a Delaware limited liability company, 27 Joshua Edwards Court, East Hampton, New York 11937, United States. Contact: Lorenz Sell, Chief Executive Officer; support@sutra.co. Role: Processor. Activities relevant to the data transferred: providing the Sutra Services as described in the Agreement.
B. Description of Transfer
Sutra Processes Customer Personal Data on a continuous basis for the duration of the Agreement, in order to host, store, transmit, display and otherwise make available content, accounts and activity within the Sutra platform on Customer's behalf.
- Categories of Data Subjects: Customer's administrators, instructors, facilitators, learners, members, and other end users invited to or registered for spaces hosted on the Sutra platform.
- Categories of Personal Data: Identifiers (e.g., name, username); contact information (e.g., email address); authentication data (e.g., password hash, authentication tokens); profile information (e.g., avatar, biography); membership and registration details; sign-in IP addresses and login activity; push notification tokens (for users of the Sutra mobile app); location information where users choose to provide it; content authored by Data Subjects within the platform (e.g., posts, comments, direct messages, survey responses, uploaded files and media, and audio that is transcribed for accessibility and search features); and usage and log data generated through the Data Subject's use of the Services.
- Special Categories of Data: None are required by the Services. Customer's obligations regarding Prohibited Personal Data — which include the special categories under Article 9 GDPR and the additional categories listed in Section 2.6 — are set out in that Section.
- Frequency of Transfer: Continuous, for the duration of the Agreement.
- Nature of Processing: Hosting, storing, transmitting, displaying, organizing and otherwise making available Customer Personal Data through the Services; providing customer support; maintaining backups; providing AI-assisted features that are enabled by default in the Services (which Customer may disable per the in-product settings, as further described on the Sub-processor Page); and providing related operational and security functions.
- Purpose of Processing: Provision of the Services to Customer in accordance with the Agreement and Customer's documented instructions.
- Duration / Retention: For the term of the Agreement and thereafter as set out in Section 11, subject to the hosting provider's standard point-in-time-recovery window (currently up to approximately seven (7) days).
- Sub-processor Transfers: As listed on the Sub-processor Page at sutra.co/subprocessors, for the duration of the engagement.
C. Competent Supervisory Authority
For Module Two transfers, the competent Supervisory Authority is the lead supervisory authority of the data exporter or, where the data exporter is not established in the EEA, the supervisory authority of the EEA Member State in which the EU representative is designated, or, in the absence of such designation, the Irish Data Protection Commission. For UK transfers, the competent Supervisory Authority is the UK Information Commissioner's Office. For Swiss transfers, the competent Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Annex 2 — Technical and Organizational Measures
This annex describes the technical and organizational measures implemented by Sutra to ensure an appropriate level of security in accordance with Article 32 GDPR. Specific measures may be updated from time to time without materially diminishing the overall level of protection.
1. Access Control and Identity Management
- Role-based separation between regular users and internal administrators.
- Multi-factor authentication enforced at the identity-provider layer for personnel access to hosting and administrative consoles (e.g., Render, Amazon Web Services).
- End-user passwords are hashed with bcrypt and must meet a minimum length of eight (8) characters.
- Scoped API tokens are used for automated access to administrative endpoints.
- Access for departing personnel is revoked promptly.
2. Encryption
- Encryption of Customer Personal Data in transit using industry-standard TLS for application traffic and outbound API integrations with Sub-processors.
- Encryption of Customer Personal Data at rest is provided by the hosting infrastructure (Render Postgres encryption at rest; Amazon S3 default server-side encryption).
- Sensitive parameters (passwords, authentication tokens, signing secrets, preview tokens, and similar) are filtered from application logs.
3. Network and Infrastructure Security
- Hosting in physically and logically secured data centers operated by reputable cloud infrastructure providers — including Render, Amazon Web Services, and Vercel — which hold recognized security certifications such as SOC 2 and ISO 27001 at the provider level.
- Network segmentation, firewalls, and infrastructure-level intrusion detection are provided by the underlying cloud platforms.
- Routine application of security patches and dependency updates.
4. Application Security
- Source code is maintained in version control. Production deploys are gated by automated continuous integration test runs.
- Errors and anomalies across all production services (the Rails application, the web frontend, and the mobile app) are monitored via a third-party error-tracking service (Sentry).
- Security-relevant actions on Sutra's Public and Admin APIs are logged, with the acting party, the action, and request metadata recorded for later review.
5. Resilience and Availability
- Continuous backups with point-in-time recovery (PITR) are provided by the hosting infrastructure (Render Postgres), with a recovery window consistent with the hosting provider's plan (currently up to approximately seven (7) days).
- Operational monitoring and alerting for production-service availability.
6. Personnel and Organizational Measures
- Personnel with access to Customer Personal Data are subject to confidentiality obligations under their engagement terms.
- Personnel are briefed on their data protection responsibilities.
7. Incident Response and Breach Notification
- Sutra's Chief Executive Officer (currently Lorenz Sell, reachable at support@sutra.co) is the designated point of contact for the assessment of security events affecting Customer Personal Data and the management of Personal Data Breach notifications under Section 8.
- Production-service errors and anomalies are surfaced by automated monitoring for triage.
8. Sub-processor Management
- Sub-processors are engaged under written agreements requiring data protection obligations equivalent to those in this DPA, consistent with Article 28(4) GDPR.
- The current list of Sub-processors is published at sutra.co/subprocessors, and Customers may subscribe to be notified of additions or changes.
Annex 3 — Authorized Sub-processors
The authoritative, current list of Sub-processors engaged by Sutra to Process Customer Personal Data is published and maintained at sutra.co/subprocessors. That page, as updated from time to time, is incorporated into this DPA by reference and constitutes the "Annex III" to the Standard Contractual Clauses. For each Sub-processor, the page identifies the entity name, the service provided, the country or region of Processing, and the categories of Customer Personal Data Processed. Customer may subscribe at the Sub-processor Page to receive email notification of additions or replacements, as set out in Section 5.2 of this DPA.
A Transfer Impact Assessment supporting Sutra's reliance on the Standard Contractual Clauses for restricted transfers is maintained internally and is available to customer auditors and competent supervisory authorities on request to support@sutra.co, subject to reasonable confidentiality undertakings.