Trust
Last updated: June 26, 2026
Sutra is the all-in-one platform for people and projects with purpose. This page summarizes how we protect customer data, disclose sub-processors, handle AI features, and support compliance reviews.
Regulatory
GDPR, UK GDPR, Swiss FADP, CCPA, and related privacy frameworks are reflected in our public legal terms.
Transfers
EU SCCs, the UK International Data Transfer Addendum, Swiss adaptations, and DPF certifications are used where applicable.
Security
Sutra uses TLS in transit, provider-managed encryption at rest, access controls, monitoring, backups, and incident-response procedures.
AI
Sutra does not use customer content to train third-party AI models. AI sub-processors are disclosed on the sub-processor page.
Legal documents
The Privacy Policy, Terms, DPA, Cookie Policy, and sub-processor list are all publicly available.
Support
Security, privacy, compliance, and data-subject-rights requests can be sent to support@sutra.co.
Available on request
Customer auditors, procurement teams, and supervisory authorities may request supporting materials such as our Transfer Impact Assessment or a wet-signed DPA, subject to reasonable confidentiality terms.
Contact support@sutra.co