If people in the EU or UK join your courses, communities, or mailing list, the GDPR applies to you — even if you're based somewhere else. The good news: most of what it asks is simply good practice, and Sutra carries a significant part of the load for you.
This article is a quick orientation. For the full plain-language guide, see GDPR for Creators.
This article is educational, not legal advice. For advice on your specific situation, please consult a qualified professional.
The key concept: you're the controller, Sutra is your processor
Your participants' data belongs to your business — you decide what to collect and why, which makes you the controller. Sutra stores and processes that data on your instructions, which makes Sutra your processor.
Two practical consequences:
Privacy requests from your participants (access, correction, deletion, export) come to you first, and Sutra supports your response.
The GDPR requires a written contract between you and Sutra. It's already in place: our Data Processing Addendum is incorporated into our Terms and binds automatically — there is nothing to sign.
Your quick checklist
Publish your own privacy notice and link it from your registration pages and website. Sutra's Privacy Policy covers Sutra, not your business.
Review your registration questions and intake forms — remove any field the program doesn't need. If you collect health or other sensitive information, ask for explicit consent in the form itself.
Keep your email lists consent-based — no purchased or imported lists without consent.
Know your playbook for a rights request: verify the request comes from the person it's about, fulfill it, and reply within one month.
Mention in your privacy notice that you use Sutra, hosted in the United States, with transfers covered by the EU Standard Contractual Clauses and related safeguards.
Bookmark Sutra's DPA and sub-processor list for your records.
How Sutra supports you
A published Article 28 DPA, binding from the moment you use the platform
International transfers papered with the EU SCCs, UK Addendum, and Swiss adaptations
Encryption in transit and at rest, with continuous database backups
Opt-in mailing lists with automatic unsubscribe handling in broadcasts
Member and contact management tools to fulfill access, correction, and deletion requests
Breach notification to you within 72 hours, so you can meet your own notification deadlines
The complete picture — including our security practices and AI sub-processors — lives on our trust page.
Common questions
Someone asked me to delete their data. What do I do?
Verify the request really comes from them, remove them and their data from your spaces, mailing lists, and contacts, and confirm to them in writing within one month. If you hold their data anywhere else — your inbox, your notes — remove it there too.
Do Sutra's AI features affect my compliance?
Sutra's AI features use the sub-processors disclosed on our sub-processor page, and customer content is not used to train third-party AI models. Default-enabled AI features can be disabled in your settings.
I'm not in the EU — does this apply to me?
If people in the EU or UK are in your programs or on your list, yes. The GDPR follows the participant, not the business.
For the full guide — including all five controller obligations and what to put in your privacy notice — see GDPR for Creators. Questions? Write to support@sutra.co.