This policy explains what personal data SutramX collects when you use our website and monitoring service, why we collect it, who we share it with, how long we keep it, and the rights you have. The same policy is published at sutramx.com/privacy.
1. Who we are
SutramX is operated by QuantumPlug Technologies LLP ("SutramX", "we" or "us"), registered at Darbhanga, Bihar, India. For personal data about our own account holders (for example, your login and billing contact details) we act as the data controller. For personal data that customers put into the service (for example, alert recipients' email addresses, or data contained in monitored responses) we act as a processor on the customer's behalf, under our Data Processing Addendum, which forms part of our Terms of Service.
2. Data we collect
- Account data: name, email address, hashed password, workspace and team membership, time zone and notification preferences, and two-factor authentication settings.
- Billing data: plan, billing country, subscription status, and invoice history. Card, UPI and other payment details are collected and processed directly by our payment providers; we do not store full card numbers.
- Monitor configuration: target URLs, hosts and ports, request settings, custom request headers, request bodies and credentials (encrypted at rest), check intervals, and alert channel details such as email addresses, chat webhooks and integration keys.
- Monitoring results: check outcomes, status codes, response timings, response snippets, certificate details, and incident history for the targets you monitor.
- Status page subscribers: email addresses that visitors submit to a status page, kept only after they confirm by email; and Slack or webhook URLs that visitors subscribe with (encrypted at rest), kept only after a test message is delivered. An address that is never confirmed is deleted 7 days after the confirmation email, and an unsubscribed one 30 days after unsubscribing.
- Mobile app: if you use the SutramX mobile app, your account email address, name and user ID, and a device identifier: the Expo push token for your device, with the device name or model, platform, operating system version and app version. We use them only to sign you in and deliver alerts to your phone, and to list the device among your signed-in sessions. The app contains no advertising or analytics SDKs and nothing it collects is used for tracking or advertising; turn off notifications, sign out (which removes the push token) or delete your account in the app to stop.
- Logs: security and operational logs such as sign-in events and sessions (device, browser, IP address), user agents, API usage, audit events (for example invitations, API key changes, exports and deletion requests), and alert delivery records; and our internal event log of activity on accounts, such as emails we sent, payments and plan changes, and sign-ups, sign-ins or requests we refused or rate-limited, which can include the email address and IP address involved.
- Website analytics: if you accept analytics cookies in the banner on sutramx.com, we use Google Analytics (provided by Google), which sets the
_gacookies to recognise returning visits and records the pages you view, how you arrived, your approximate location (from your IP address, which Google does not store) and your device and browser. Google signals and ad personalisation are turned off. - Page performance: on sutramx.com our network provider Cloudflare measures how fast pages load with Cloudflare Web Analytics. It sets no cookies and uses no browser storage, does not recognise returning visitors and does not build a profile of you; it receives the page address, load timings and your browser details, and sees your IP address as part of the connection. It is not used in the SutramX dashboard or on status pages.
- Product analytics: if you accept analytics cookies on sutramx.com (the SutramX dashboard follows that choice and never asks separately), we also use PostHog (provided by PostHog, Inc. and hosted in the United States), which sets
ph_cookies and local storage to recognise returning visits across sutramx.com and app.sutramx.com. It records the pages you view, the buttons and links you click, actions you take in the dashboard (for example creating a monitor or starting a checkout), how you arrived, your approximate location (from your IP address, which PostHog does not store), your device and browser, and recordings of how pages are used (session replays) in which everything you type into forms is hidden (in the dashboard, all text on screen is hidden too). In the dashboard these events are linked to your internal user ID and plan, never to your name or email address. Web addresses are stored without their query string, so links that carry a token are never recorded. Public status pages, the mobile app and SutramX staff acting on your account are never tracked. We keep analytics events for up to 12 months and session recordings for up to 30 days. We use it to see where people get stuck and to improve the product, never for advertising. - Your analytics choice: the legal basis for both is your consent; you can withdraw it at any time with “Cookie settings” in the website footer (Settings → Analytics cookies here links there), and the cookies are then deleted. Until you accept, neither script is loaded and nothing is sent to Google or PostHog; if you decline, they are never loaded. One choice covers sutramx.com and the dashboard. So that we can show what you chose, each Accept or Decline (and a choice made before October 2026, once, on your next visit) is also recorded on our servers under a random consent ID that your browser keeps with the choice (
sx_consent_id). The record holds only that ID, whether you accepted, declined or withdrew, the version of the banner you saw, the time and, when you accept, PostHog's random visitor ID; never your IP address, browser details or location. PostHog events also carry the consent ID. Records are deleted 3 years after they are made. - How you found us: when you create an account we store, with it, the optional answer to “How did you hear about us?” (and any short text you type for “Other”), the campaign tags on the link you arrived through (
utm_*andref, for example a SutramX status page footer), the website that linked to you (its host and path, without query strings), the first page you opened and when, and whether you signed up with a password, Google or GitHub. We use it only to count which channels bring signups, never for advertising, and it is not shared with anyone. Without analytics consent the tags are held in the browser tab's memory only; with it they are kept in browser storage (sx_signup_attribution, up to 30 days) so they survive a reload. The record is included in your data export and deleted with your account. - Communications: messages you send to support and related correspondence.
- Referral visits: if you follow a partner's referral link, we record the referral code, the landing page, the referring site's host name and a salted hash of your IP address (not the address itself), and, if you sign up, which partner referred your account. The visit record is deleted after 13 months; a signup stays credited to the partner.
3. How we use data, and our legal basis
We use personal data only for the purposes below. Under the EU and UK GDPR, each purpose rests on the legal basis shown next to it.
| Purpose | Legal basis |
|---|---|
| Creating and running your account and workspaces: sign-in, checks, alerts, reports, status pages, the mobile app and support | Contract: needed to provide the service you signed up for (Art. 6(1)(b)) |
| AI incident summaries, postmortems and status updates, on request or automatically on plans that include them | Contract: a feature of your plan (Art. 6(1)(b)) |
| Payments, invoices, tax and accounting records | Contract, and legal obligation to keep tax and accounting records (Art. 6(1)(b) and (c)) |
| Service and account emails: billing notices, plan-limit notices and security alerts | Contract (Art. 6(1)(b)); for security alerts also our legitimate interest in protecting your account (Art. 6(1)(f)) |
| Keeping the service secure: sign-in and audit logs, fraud and abuse prevention, error diagnostics | Legitimate interests in protecting our users and the service (Art. 6(1)(f)) |
| Occasional product news emails to account holders | Legitimate interests in telling customers about the service (Art. 6(1)(f)); you can opt out with the link in every such email or in your notification settings |
| Learning how people find SutramX: the optional "How did you hear about us?" answer and the campaign tags on the link you signed up from | Legitimate interests in knowing which channels bring customers (Art. 6(1)(f)); the answer is optional, and the tags are stored on your device only with your analytics consent |
| The State of uptime newsletter, if you sign up for it | Consent, given by confirming your address, which you can withdraw at any time with the one-click unsubscribe link in every issue (Art. 6(1)(a)); the record of that consent, to show that we have it (Art. 6(1)(c) with Art. 7(1)) |
| Crediting a partner for a referral | Legitimate interests in running the partner programme (Art. 6(1)(f)); the referral cookie itself only with your consent |
| Analytics: Google Analytics on the marketing website, and PostHog product analytics on the website and in the dashboard | Consent, which you can withdraw at any time (Art. 6(1)(a)); the record of your choice, to show that we have your consent (Art. 6(1)(c) with Art. 7(1)) |
| Answering legal requests and enforcing our terms | Legal obligation (Art. 6(1)(c)) or legitimate interests (Art. 6(1)(f)) |
Under India's DPDP Act, we process your personal data with the consent you give when you sign up or submit it, and for the legitimate uses the Act allows, such as data you provide voluntarily for a specified purpose and complying with the law. Where we rely on legitimate interests, you can object (section 8). For data we process as a processor for a customer, such as alert recipients or status page subscribers, the customer decides the purpose and legal basis.
We do not sell personal data, and we do not use monitoring data for advertising.
4. Where your data is stored
- Primary hosting and processing: the application, API, database and monitoring workers run on Amazon Web Services in Frankfurt, Germany (EU, AWS region eu-central-1).
- Backups: encrypted database backups are stored with Amazon Web Services in the USA (AWS region us-east-1, N. Virginia).
- Operational logs: application logs, which can include IP addresses and request details, are kept with Amazon Web Services in the USA (AWS region us-east-1) for 14 days.
- Data exports: an export you request is stored temporarily with Cloudflare R2 and deleted 7 days after it is created; download links expire after 1 hour.
- Checks: checks run from our checker locations, currently Frankfurt, Germany (hosted on AWS), Arizona, USA (hosted by Hostinger) and Mumbai, India (hosted by Hostinger). A checker receives the settings it needs to run your checks and sends back the results.
5. Sub-processors
We share data with the following providers only as needed to run the service. The same list, with notice of changes, is published at sutramx.com/subprocessors.
Amazon Web Services (AWS)
Hosting of the application, API, database, monitoring workers, the marketing website, our internal admin console and the Frankfurt checker; outgoing email (Amazon SES) for transactional, alert and newsletter emails, and the delivery reports it returns (delivered, bounced, marked as spam); encrypted database backups; operational logs (kept 14 days).
Location: Germany (eu-central-1, Frankfurt); backups and operational logs in the USA (us-east-1, N. Virginia)
Hostinger
Hosting of the Arizona and Mumbai checkers; outgoing email (SMTP) for transactional and alert emails.
Location: Checkers in the USA (Arizona) and India (Mumbai); email per provider
Cloudflare
DNS, network security, and content delivery for our websites and API; cookieless page-load measurement on the marketing website (Cloudflare Web Analytics).
Location: Global edge network
Cloudflare R2
Temporary storage of data exports you request (deleted after 7 days).
Location: Global (Cloudflare R2)
Dodo Payments
USD payments; acts as merchant of record.
Location: Per provider
Razorpay
INR payments, including UPI autopay.
Location: India
Google Web Risk
Screening monitor target URLs for known malicious sites; receives only the scheme, host and path, never the query string, credentials, headers or bodies.
Location: United States
Globalping (jsDelivr)
Last-mile checks on plans that include them: measures your monitored host from home and mobile networks; receives only the host name, port and path, never headers, credentials or bodies.
Location: Global (probe network)
Google Analytics (Google)
Visitor analytics for the marketing website sutramx.com, only if you accept analytics cookies; not used in the SutramX dashboard or apps.
Location: United States
PostHog
Product analytics for the marketing website and the SutramX dashboard, only if you accept analytics cookies: page views, feature usage and session recordings with everything you type hidden; linked to your user ID, never your name or email; not used on public status pages or in the mobile app.
Location: United States
Twilio
SMS and voice call alerts, and WhatsApp alerts sent through Twilio.
Location: United States
Meta (WhatsApp Business Platform)
WhatsApp alerts sent through the WhatsApp Cloud API.
Location: Global
Microsoft (Azure Bot Service)
Delivering alerts through the SutramX app for Microsoft Teams, when a customer adds it to Teams: receives the alert text and the Teams conversation it goes to.
Location: Global (Microsoft cloud)
Google (Google Chat API)
Delivering alerts through the SutramX app for Google Chat, when a customer adds it to a Chat space: receives the alert text and the space it goes to.
Location: Global (Google cloud)
Telegram
Telegram alerts sent through the SutramX Telegram bot.
Location: Global
OpenAI (OpenAI API)
Drafting AI incident summaries, postmortems and status page updates, from redacted incident facts (no alert recipients, names, request headers or bodies, or full monitored URLs): on request, and automatically for incidents open more than 5 minutes on plans that include AI incident summaries. OpenAI does not use API data to train its models.
Location: United States
Sentry
Error diagnostics for the API; error reports are scrubbed of credentials and request bodies.
Location: United States
Expo (Expo push notification service)
Delivering push alerts to the SutramX mobile app, through Apple Push Notification service and Firebase Cloud Messaging; receives the device push token and the alert text.
Location: United States
Browser push services (Google, Mozilla, Apple, Microsoft)
Delivering encrypted browser push alerts you turn on.
Location: Per browser vendor
If you connect third-party services yourself (such as Slack, Discord, Microsoft Teams and Google Chat incoming webhooks, Mattermost, PagerDuty, Opsgenie, GitHub, custom webhooks, and Google or GitHub sign-in), data is sent to those services on your instruction and is governed by their own terms.
6. Retention
- Raw check results (every individual check) are kept for 90 days.
- Aggregated daily uptime history is kept for 90 days on the Free plan, 12 months on Starter and 24 months on Growth and Pro. If a paid plan ends, its longer history is kept for 30 more days before the new plan's limit applies. Incidents and status page history are kept while your workspace exists.
- Incident timelines are kept for about 13 months after the incident is resolved.
- Alert delivery logs are kept for about 90 days, and other operational logs for limited periods appropriate to their purpose.
- Data exports are deleted 7 days after they are created.
- Account data is kept while your account is active. Your account security log (password, two-factor, email and sign-in method changes and session revocations) is kept for 2 years and is deleted with your account. The owners of the workspaces you belong to see these changes in their workspace activity log, without your IP address.
- Sign-in sessions (device, browser and IP address) are deleted 90 days after they end (sign-out, revocation or expiry). Email change requests are deleted 90 days after they were used, cancelled or expired; the change itself stays in your account security log.
- Workspace activity logs are kept for 2 years, including after the workspace is deleted (without the names, email addresses and IP addresses of deleted accounts; see section 7).
- Our internal event log (see Logs in section 2) is kept for 180 days.
- Billing records (payments, invoices, alert-credit and lifetime-deal purchases and tax documents) are kept while your account exists and, after you delete it, until 8 years after the end of the Indian financial year (April to March) they belong to, as Indian tax and company law requires; they are then deleted automatically. Each record keeps the buyer details (name, email, billing address, tax ID and country) as they were when it was created. Records created before we started keeping that copy in October 2026 carry the details as they were on that date instead.
- Records of your analytics choice (a random consent ID, the choice, the banner version and the time; no IP address) are kept for 3 years after each choice.
- Backups: deleted data can remain in our encrypted database backups until they expire, within about 40 days.
7. Deletion and export
Anyone with an account can download a JSON copy of their own personal data from Settings → Danger zone → Download my data. Workspace owners can also export a whole workspace and delete the workspace and account from the dashboard ( Settings → Danger zone), or ask us by email. When you delete your workspace or account, it is scheduled for deletion; you can cancel within 30 days, after which the data is permanently deleted. At that point we also delete your sign-in history, queued emails, alert delivery records and the entries about your account in our internal event log, and remove your email address, name, IP address and browser details from support tickets and workspace activity logs; the text of support conversations and the activity entries themselves are kept without them. We also ask PostHog to delete the analytics events and session recordings linked to your user ID. Status page subscribers can unsubscribe with the link in every email, Slack message or webhook delivery.
After your account is deleted we keep only the following, each for a limited purpose:
| What we keep | Why (legal basis) | How long |
|---|---|---|
| Billing records: payments, invoices, alert-credit and lifetime-deal purchases and tax documents, with the buyer details on them (name, email, billing address, tax ID, country) | Indian tax and company law requires us to keep accounting records (legal obligation, Art. 6(1)(c)) | 8 years after the end of the Indian financial year (April to March) each record belongs to, then deleted automatically |
| Our email suppression list: your email address and why we stopped emailing it (it bounced, you marked an email as spam, or you unsubscribed) | So that we never email an address that bounced, complained or opted out again (legitimate interests, Art. 6(1)(f), and respecting your objection) | No fixed period: as long as we send email. Ask us to remove it if you want; we may then email that address again |
| Our staff audit log: actions SutramX staff took, including on your account (it can name your email address) | Accountability for, and the security of, staff access to customer accounts (legitimate interests, Art. 6(1)(f)) | 2 years |
| Payment notifications from Razorpay or Dodo Payments, which can include your name, email and billing details | Detecting duplicate or forged payment events and resolving payment questions (legitimate interests, Art. 6(1)(f)) | 180 days (configurable between 90 days and 2 years) |
| Security records in our internal event log of sign-ups, sign-ins or requests we refused or rate-limited: unlinked from your account and with your email address removed (the IP address involved stays) | Preventing abuse of the service and protecting accounts (legitimate interests, Art. 6(1)(f)) | Up to 180 days from when they were recorded |
| Delivery, bounce and spam-complaint reports from our email provider, with the recipient address | Keeping our email deliverable and handling abuse reports (legitimate interests, Art. 6(1)(f)) | 90 days |
| Safety checks of monitored URLs that we blocked as malicious or unsafe: the URL and the verdict, no longer linked to you or your account | Preventing abuse of the service (legitimate interests, Art. 6(1)(f)) | No fixed period |
| The text of your support conversations, without your email address, name, IP address or browser details (anything you wrote in a message stays in it) | Our support history and establishing or defending legal claims (legitimate interests, Art. 6(1)(f)) | No fixed period; ask us and we will delete it unless we need it for a claim |
Deleted data can also remain in encrypted backups until they expire (see section 6). If another customer added your email address to their workspace (as a team invitation, alert recipient, status page subscriber or on-call member), or their workspace activity log names you, that data is theirs: it stays until they remove it or delete their workspace.
8. Your rights
Depending on where you live, including under the EU/UK General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act), you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, to withdraw consent where processing is based on consent, and to nominate a person to exercise your rights. You also have the right to complain to your local data protection authority or the Data Protection Board of India. If we process your data as a processor for one of our customers, please contact that customer first; we will help them respond.
9. International transfers
Your data is hosted in Germany, backed up in the USA, and processed by the sub-processors and checker locations listed above, so it may be processed outside your country of residence. Where required, we rely on appropriate safeguards for transfers of personal data: the European Commission's standard contractual clauses (Decision (EU) 2021/914), with the UK Addendum and Swiss amendments where they apply, as set out in our Data Processing Addendum.
10. Security
Data is encrypted in transit (HTTPS), and sensitive fields such as monitor credentials (request headers, request bodies and credential query parameters) and integration secrets are encrypted at rest. Access is restricted to authorised systems and staff. Passwords are hashed, API keys and invitation tokens are stored as digests, and two-factor authentication is available. To report a vulnerability, email security@sutramx.com. No system is perfectly secure; if a breach affects your personal data, we will notify you and the relevant authorities as required by law. We keep an internal record of every personal data breach: what happened, its effects and what we did about it.
11. Cookies
We use strictly necessary cookies and local browser storage, such as the cookies that keep you signed in and protect sign-in and two-factor verification. The only optional cookie is the referral cookie (sx_ref): if you arrive through a partner's referral link and choose to have it remembered, it stores the referral code for up to 60 days (or the partner programme's window, never more than 365 days) so the partner can be credited if you sign up later. It is set only with your consent; if you decline, nothing is stored and a signup in the same visit is still credited through the link itself. Our legal basis for the related attribution is our legitimate interest in running the partner programme. We use no advertising cookies, and analytics cookies (Google Analytics on the marketing website, PostHog on the website and in the dashboard) only if you accept them (see section 2). See our Cookie Policy.
12. Children
SutramX is a service for businesses and professionals and is not directed at children. You must be at least 18 years old (or the age of majority where you live, if higher) to create an account or use the service. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has given us personal data, contact support@sutramx.com and we will delete it.
13. Changes to this policy
We may update this policy as the service changes. We will post the new version here with a new date and, for material changes, notify account holders by email.
14. Contact
For privacy questions or to exercise your rights, contact our grievance and privacy officer at support@sutramx.com. We respond within 30 days. You can also write to QuantumPlug Technologies LLP, Darbhanga, Bihar, India. Data subjects in the EU, the UK or Switzerland can contact us directly at the same address for any question about their personal data or to exercise their rights.