← Policies index
VESPA Academy

Data Flow Summary

Version v1.0 · August 2026

How student and staff personal data moves through VESPA Academy at each stage. Intended for school procurement / DPIA teams (DfE-style “walk through the data”).

Stage-by-stage

1. Onboarding / roster
School admins create accounts manually, CSV import, or MIS sync (Wonde / Microsoft Graph / Google Admin SDK where enabled). Fields may include name, email, DOB, year/tutor group, gender, identifiers. Data lands in Supabase EU (eu-north-1) via portal APIs on Vercel (iad1).
2. Questionnaire & scoring
Students answer VESPA items in the authenticated portal. Responses and dimension scores are stored in the EU database. Staff see school-scoped reports and filters.
3. Coaching activities & free text
Goals, reflections, activity responses and related artefacts are stored against the student record. Access is role-based (student / staff of that school).
4. Optional AI features (user-invoked)
When a user starts an AI feature (e.g. UniGuide, Study Planner AI, coaching helpers), the minimum prompt needed for that request is sent to OpenAI (US, SCCs). May include first name / school context / questionnaire or chat content. Email is not sent for Study Planner generation. Responses may be stored back in the EU database for continuity. Details: AI Usage Policy.
5. Benchmarking
National normative tables are anonymous aggregates (no student or school identifiers). School-level analytics remain visible only to that school's authorised users.
6. Email notifications
Transactional messages (welcome, notifications) via SendGrid (US, SCCs) using the recipient address and limited context needed for the email.
7. Marketing website (separate from portal)
Cookiebot + GA4 + consent-gated ad tags may load on vespa.academy marketing pages only — not in the authenticated student/staff portal.
8. Leave / erasure
On Controller instruction, personal data is removed from production systems (target within 30 days; currently via documented runbook). Written confirmation available on request. Related email-keyed stores included in the checklist.
9. 4Sight CRM (controller-side for 4Sight)
School commercial contacts and CRM operations (including Anthropic for internal drafting) are 4Sight's own controller processing — not student portal coaching.

What does not happen

Canonical sub-processors: SPL-2026.08. DPA: v2.0 preview.


© 2026 VESPA Academy — 4Sight Education Ltd