Privacy
Last updated 2 September 2026
Who this covers
This describes how [to supply: registered entity name and number] (“we”) handles information in the Sutra platform. It applies to the people who sign in — the operations team and the staff of the organisations whose buildings are monitored.
The platform has no public sign-up. Every account is created by the operations team on behalf of an organisation, so we hold information about people because their employer asked us to.
Our role
For most of what is described here we act on your organisation’s instructions rather than our own: your organisation decides who gets an account, which sites are monitored and what happens to the figures. In data-protection terms your organisation is the controller of that information and we process it for them, under the agreement between us.
We act on our own account for a narrow set of things — the records we must keep to run and secure the platform, such as sign-in activity, the audit log and our own billing records. Because of that split, a request about your own account is usually answered fastest through your organisation’s administrator, and we will tell you if a request needs to go that way.
What we hold
- Account details. Full name, User ID, email address and optionally a phone number. Passwords are never stored — only an Argon2id hash, which cannot be reversed to recover the password.
- Meter readings. Consumption figures read from the energy and water meters installed at the monitored sites, with the time of each reading. These describe a building, not a person.
- A record of actions. Significant changes — creating an organisation or a user, registering a meter, issuing or revoking an authority key — are written to an append-only audit log with who did them and when.
- Sign-in activity. Session records, failed sign-in counts and lockout state, kept so an account can be protected against password guessing.
What we do not do
There are no advertising or analytics trackers in this application. It loads no third-party scripts, sets no advertising cookies, and does not build a profile of you or sell information to anyone.
Nothing here makes a decision about a person automatically. Access, alerts and reports follow rules an operator configured; no profiling or automated decision-making with a legal or similarly significant effect takes place. The platform is a workplace tool and is not directed at children.
The only cookie the platform sets is the one that keeps you signed in. It is httpOnly, so no script can read it, and SameSite=Strict, so no other site can cause it to be sent. It is strictly necessary for the service to function.
Who it is shared with
- The certifying authority. Where a project is being certified, consumption figures for that project are made available to the authority through a key scoped to it. The key reaches that project and no other, and every request is recorded with its time and outcome. Personal details of your staff are not included.
- Meter manufacturers. We read from their systems to collect your readings. We do not send them information about you.
- Infrastructure providers. The companies that host the platform, store its files and deliver its email. They hold information because they run the service for us, not for their own purposes, and are named under “Where it is held” below.
Beyond this we do not share information with anyone, except where we are legally required to.
Where it is held
The platform and its database run in [to supply: hosting provider and region]. Rendered reports and uploaded certificates are stored separately in [to supply: object storage provider and region], and email is sent through [to supply: email provider and region].
Where those regions are not the same country your organisation operates in, information crosses a border to reach them. That transfer is necessary to provide the service, and it is made under [to supply: transfer mechanism relied on]. We will tell you before we move your data to a different country.
Keeping organisations apart
Each organisation’s data is separated at the database level rather than only in application code, so a query made on behalf of one organisation cannot return another one’s rows. Within an organisation, people are granted specific projects and buildings, and every list, chart, report and download narrows to that grant.
How long it is kept
Meter readings are retained for [to supply: retention period for readings]. Account records are retained for [to supply: retention period after an account is closed]. Audit records are retained for [to supply: audit log retention period] because they exist to show what happened.
If something goes wrong
If information is lost, exposed or accessed by someone who should not have reached it, we will tell the affected organisation without undue delay and in any case within [to supply: breach notification window], describing what happened, what it affects and what we are doing about it. Where a regulator must also be told, we will do that within the period the law sets.
The audit log exists partly for this: it is append-only and cannot be edited or deleted, even by us, so an investigation has a record that has not been tidied up after the fact.
Changing a provider
We will give you [to supply: sub-processor change notice period] before adding or replacing a provider that would hold your information, so you have the opportunity to object before it happens.
Your rights
You may ask what we hold about you, ask for it to be corrected, or ask for it to be deleted where we are not required to keep it. Because accounts belong to the organisation that asked for them, some requests are best made through your own organisation’s administrator.
These rights, and how disputes are resolved, are governed by [to supply: governing law and jurisdiction].
Complaints
If you think we have handled your information wrongly, tell us first — we would rather fix it than have you find out from somebody else. You also have the right to complain to the data-protection regulator in your country, and to [to supply: supervisory authority for our jurisdiction] where we are established. Complaining to us first does not take that right away.
Changes to this notice
When this notice changes we update the date at the top of the page. Where a change materially affects what we do with your information — a new purpose, a new provider holding it, a new country it is held in — we will tell the affected organisations [to supply: notice period for material privacy changes] in advance rather than relying on you to re-read the page.
Contact
Write to [to supply: contact address for privacy requests]. We respond within [to supply: response window].