Skip to content
SutramX
  • All features
  • All guidesAll free toolsCompare SutramX
  • All use cases
  • Documentation
  • Integrations
  • Pricing
Sign inStart free
SutramX
Pricing
Docs & HelpIntegrations
Start freeSign in

Data Processing Addendum

Last Updated: October 6, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Terms") between QuantumPlug Technologies LLP, which operates SutramX ("SutramX", "we" or "us"), and the customer that accepted the Terms ("Customer"). It is incorporated into the Terms and applies automatically, with no signature required, whenever SutramX processes Customer Personal Data on Customer's behalf. If you need a countersigned copy for your records, email support@sutramx.com.

1. Definitions

  • Data Protection Laws: the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as retained in UK law and the UK Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), India's Digital Personal Data Protection Act, 2023, and any other data protection law that applies to the processing under the Terms.
  • Customer Personal Data: personal data that Customer or its users submit to the Service, or that the Service collects on Customer's behalf, and that SutramX processes as a processor. It does not include data SutramX processes as a controller (such as account, billing and security data described in the Privacy Policy).
  • Sub-processor: a third party SutramX engages to process Customer Personal Data.
  • SCCs: the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • Terms such as "controller", "processor", "data subject", "personal data", "processing" and "personal data breach" have the meanings given in the GDPR.

2. Roles

For Customer Personal Data, Customer is the controller (or a processor acting for its own controller) and SutramX is the processor (or sub-processor). Where Customer is a Data Fiduciary under India's Digital Personal Data Protection Act, 2023, SutramX acts as its Data Processor on the same terms. Each party complies with the Data Protection Laws that apply to it. Customer is responsible for having a lawful basis for the processing and for the accuracy of the data and instructions it gives us.

3. Details of the processing

The details of the processing are set out in Annex 1.

4. Customer's instructions

SutramX processes Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law, in which case we will tell Customer before processing unless the law prohibits it. The Terms, this DPA, and Customer's configuration and use of the Service are Customer's complete instructions. We will tell Customer promptly if, in our opinion, an instruction infringes Data Protection Laws.

5. SutramX's obligations

  • Confidentiality: SutramX ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality obligations and accesses it only as needed to provide, secure and support the Service.
  • Security: SutramX implements the technical and organisational measures in Annex 2, appropriate to the risk as required by Article 32 GDPR. We may update them, as long as the overall level of protection is not reduced.
  • Data subject requests: taking into account the nature of the processing, SutramX assists Customer by appropriate measures in responding to requests from data subjects to exercise their rights. The dashboard lets Customer view, correct, export (JSON) and delete Customer Personal Data. If SutramX receives a request directly, it will direct the data subject to Customer and will not respond itself except to confirm the request was passed on, unless Customer authorises it or the law requires it.
  • Assistance: taking into account the nature of the processing and the information available to SutramX, we assist Customer with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation with supervisory authorities).
  • Records and information: SutramX makes available to Customer the information necessary to demonstrate compliance with Article 28 GDPR, as described in section 9.

6. Sub-processors

Customer gives SutramX general written authorisation to engage Sub-processors. The current list, with each provider's purpose and location, is published at sutramx.com/subprocessors. SutramX will:

  • impose on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA;
  • give at least 30 days' notice before adding or replacing a Sub-processor, by updating the list and emailing workspace owners, except where an urgent change is needed to keep the Service secure or running, in which case we notify as soon as reasonably possible;
  • remain responsible to Customer for its Sub-processors' performance of their obligations.

Customer may object to a new Sub-processor on reasonable data protection grounds by emailing support@sutramx.com within the notice period. We will work with Customer in good faith to address the objection. If we cannot, Customer may terminate the affected Service by closing its workspace before the change takes effect.

7. Personal data breaches

SutramX will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and mitigate its effects. Where not all information is available at once, we will provide it in phases without undue further delay. We will take reasonable steps to contain and remedy the breach and will cooperate with Customer in meeting its own notification obligations. Notification is not an acknowledgement of fault or liability.

8. Deletion and return

While the account is active, Customer can export its workspace data from the dashboard at any time. When Customer deletes its workspace or account, or the Terms end, SutramX deletes Customer Personal Data after the 30-day cancellation window described in the Privacy Policy, except the records listed in section 7 of the Privacy Policy, which are kept for the purposes and periods stated there (for example billing records that tax law requires us to keep). Data in encrypted backups is removed as those backups expire on their rolling schedule (daily database backups are kept for 30 days) and is not restored into the live service in the meantime except to recover from a failure. On request, we will confirm deletion in writing.

9. Audits

SutramX will answer Customer's reasonable written questions and security questionnaires about the processing, and make available the information necessary to demonstrate compliance with this DPA. SutramX does not currently hold a third-party security certification. If that information is not sufficient, or a supervisory authority requires it, Customer (or an independent auditor bound by confidentiality and not a competitor of SutramX) may audit SutramX's compliance with this DPA, no more than once in any 12 months except after a personal data breach, on at least 30 days' written notice, during business hours, at Customer's cost, and in a way that does not disrupt the Service or compromise other customers' data. Audits of Sub-processors are carried out through the information and reports those providers make available.

10. International transfers

Customer Personal Data is hosted in Germany (EU) and may be accessed from India by SutramX and processed by Sub-processors in the locations shown on the sub-processor list. Where processing under the Terms involves a transfer of personal data to a country that does not have an adequacy decision:

  • EU (GDPR): the SCCs are incorporated into this DPA by reference, with Customer as data exporter and SutramX as data importer. Module 2 (controller to processor) applies where Customer is a controller, and Module 3 (processor to processor) where Customer is a processor. For both modules: the optional docking clause in Clause 7 does not apply; under Clause 9(a), Option 2 (general written authorisation) applies with the notice period in section 6 of this DPA; the optional language in Clause 11(a) does not apply; under Clause 13, the supervisory authority is the one competent for the data exporter; under Clause 17, the SCCs are governed by the law of the EU Member State in which the data exporter is established or, where that law does not allow for third-party beneficiary rights, by the law of Ireland; and under Clause 18, disputes are resolved by the courts of that same Member State. Annex I of the SCCs is completed by the parties named above and Annex 1 of this DPA, Annex II by Annex 2 of this DPA, and Annex III by the sub-processor list.
  • United Kingdom: for transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force 21 March 2022) is incorporated by reference and amends the SCCs as set out above. Tables 1 to 3 of that Addendum are completed with the information in this DPA and its annexes, and for Table 4 both the importer and the exporter may end the Addendum as set out in its Section 19.
  • Switzerland: for transfers subject to the FADP, the SCCs apply as set out above with these changes: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and references to "Member State" do not prevent data subjects in Switzerland from bringing claims in their place of habitual residence (Switzerland).

SutramX ensures that its Sub-processors located outside the EU, the UK or Switzerland receive Customer Personal Data under an appropriate transfer mechanism, such as the SCCs or an adequacy decision (including the EU-U.S. Data Privacy Framework where the provider is certified).

11. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws or the SCCs do not allow such a limitation. If there is a conflict, the SCCs (where they apply) prevail over this DPA, and this DPA prevails over the rest of the Terms. This DPA stays in force for as long as SutramX processes Customer Personal Data. We may update it as described in the Terms; changes that reduce the protection of Customer Personal Data will not apply without Customer's agreement unless required by law.

12. Contact

Questions about this DPA or the processing of Customer Personal Data: support@sutramx.com, or write to QuantumPlug Technologies LLP, Darbhanga, Bihar, India. Security issues: security@sutramx.com.

Annex 1: Details of the processing

  • Subject matter: SutramX's provision of the Service to Customer: uptime, API, cron and DNS monitoring, alerting, incident management, and status pages.
  • Duration: the term of the Terms, plus the period until deletion under section 8.
  • Nature of the processing: collection, storage, structuring, retrieval, transmission (for example sending alerts and status page notifications), and erasure, by automated means.
  • Purpose: to provide, secure and support the Service in accordance with the Terms and Customer's instructions.
  • Categories of data subjects: Customer's users and team members; people Customer adds as alert recipients or on-call responders; subscribers to Customer's status pages; and any individuals whose data appears in content Customer monitors or enters into the Service.
  • Categories of personal data: names; email addresses; phone numbers (for SMS, voice and WhatsApp alerts); chat and integration identifiers (such as Telegram chat IDs and webhook URLs); IP addresses and user agents; credentials and headers Customer attaches to monitors; and any personal data contained in monitored responses, incident notes, status page updates or support messages.
  • Special categories: none are intended. Customer should not submit special category data to the Service.
  • Frequency of transfer: continuous, for as long as the Service is used.
  • Retention: as described in the Privacy Policy (for example, raw check results for 90 days and alert delivery logs for about 90 days) and section 8 of this DPA.

Annex 2: Technical and organisational security measures

These are the measures SutramX has in place today. They are described in more detail on our Security page.

  • Encryption in transit: all traffic to the dashboard, API and status pages uses TLS 1.2 or newer; database backups are uploaded only over HTTPS.
  • Encryption at rest: monitor credentials (request header values, request bodies, passwords and tokens, and credential query parameters in monitored URLs), browser check secrets, integration secrets and two-factor authentication seeds are encrypted with AES-256-GCM before storage, with versioned keys that can be rotated; database backups are stored with server-side encryption.
  • Authentication: passwords are stored as salted hashes; API keys and invitation tokens are stored only as digests; optional TOTP two-factor authentication for every user, and SSO/SAML on eligible plans; two-factor authentication is required for staff access to the admin console; re-authentication is required for sensitive account changes; users can review and sign out other sessions.
  • Access control: workspace roles (owner, member, viewer) and read-only API keys limit who can change data; staff access to production is limited to authorised personnel; backup storage uses a dedicated, least-privilege credential.
  • Abuse and attack protection: rate limiting on sign-in, signup and API endpoints; security headers; network protection through Cloudflare; monitor targets are validated and requests to loopback, cloud metadata and private network addresses are blocked, including at connection time (SSRF protection).
  • Logging: audit records of security-relevant events (such as invitations, API key changes, exports and deletion requests) and sign-in sessions; operational logs are kept for 14 days; error reports are scrubbed of credentials and request bodies.
  • Availability and recovery: daily encrypted database backups with continuous archiving, stored off the primary host in versioned storage.
  • Data minimisation and retention: checkers receive only the settings they need to run a check; AI drafting receives redacted incident facts only; retention periods as listed in the Privacy Policy; deletion after a 30-day cancellation window.
  • Vulnerability management: a published channel for reporting vulnerabilities (security@sutramx.com).

Annex 3: Sub-processors

The authorised Sub-processors are those listed at sutramx.com/subprocessors, as updated under section 6.

SutramX

Uptime, API and cron monitoring from 3 probe regions, with SSL and domain expiry reminders. On paid plans, failures are confirmed across regions before anyone is paged.

  • Get it onGoogle Play
  • Coming soon on theApp Store

State of uptime: a monthly email of the vendor outages SutramX confirmed.

One email a month. Unsubscribe in one click. How we handle your address.

  • Start free
  • Pricing
  • Sign in
  • System status
  • Documentation
  • support@sutramx.com

Product

  • Why This Alert
  • Vendor Outage Detection
  • Indian ISP Checks
  • MCP Server Monitoring
  • Uptime Monitoring
  • SSL Certificate Monitoring
  • API Monitoring
  • Public Status Pages
  • Alerting & Escalation
  • Multi-Region Probes
  • Ping, Port, UDP & Cron
  • Reliability Insights
  • Integrations
  • All features

Free Tools

  • SLA Uptime Calculator
  • Downtime Cost Calculator
  • On-Call Cost Calculator
  • Percentile Calculator
  • Check Interval Planner
  • HTTP Status Code Reference
  • All tools

Use Cases

  • SaaS Platforms
  • E-Commerce
  • Developers & Indie Hackers
  • All use cases

Guides

  • What Is Uptime Monitoring?
  • Uptime Monitoring Services Compared
  • Reducing False Alerts
  • Monitor Blocked by Firewall
  • Incident Response Basics
  • Status Page Best Practices
  • All guides

Compare

  • UptimeRobot alternative
  • Freshping alternative
  • Better Stack alternative
  • Pingdom alternative
  • Opsgenie alternative
  • All comparisons

Solutions

  • How We Check
  • Uptime Monitoring India
  • WhatsApp Uptime Alerts
  • Uptime on Your Phone
  • Status Page Features
  • Developers & API
  • Switch to SutramX
  • Switch From Freshping
  • Switch From UptimeRobot

Company

  • About SutramX
  • Contact
  • FAQ
  • Changelog

© 2026 SutramX. All rights reserved.·Powered by QuantumPlug Technologies

  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Cookie Policy
  • Data Processing Addendum
  • Sub-processors
  • Uptime Target
  • Security Center

We'd like to use analytics cookies (Google Analytics and PostHog) to understand how sutramx.com and the SutramX app are used. They are only set if you accept. See our Cookie Policy.