GDPR for Creators
A plain-language guide to staying GDPR compliant while running your courses, communities, memberships, coaching programs, and mailing lists on Sutra.
Your role
Most Sutra creators are controllers for their member, client, subscriber, and participant data.
Sutra's role
Sutra generally acts as processor for customer personal data under the published DPA.
DPA
The Data Processing Addendum is already incorporated into the Terms and available at /dpa.
Sub-processors
Sutra maintains a public sub-processor list and update process at /subprocessors.
Rights requests
Creators should respond to participant requests and Sutra supports those responses as required by law.
Security
Sutra summarizes technical and organizational measures in the DPA and Trust page.
Start with the core documents