Last updated: August 2026 · Version v2.0
4Sight Education Ltd (“the Company”), trading as VESPA Academy, is committed to protecting the rights and freedoms of individuals in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy sets out how the Company meets its obligations and ensures that all staff, contractors, and partners understand their responsibilities when handling personal data.
Roles differ depending on the activity:
| Activity | Our role | Lawful basis |
|---|---|---|
| Providing the VESPA coaching platform (student/staff data) | Processor | Determined by the school (controller) — commonly public task and/or contract; we act on documented instructions under the DPA |
| Student psychometric assessments and coaching features | Processor | As instructed by the school; appropriate safeguards for minors remain the school's responsibility as controller |
| Marketing to prospective schools | Controller | Legitimate interests (with opt-out) |
| Responding to enquiries | Controller | Legitimate interests / consent |
| Payment processing and billing | Controller | Contract |
| Legal and regulatory compliance | Controller / as required | Legal obligation |
In accordance with Article 5 of the UK GDPR, we ensure that personal data is:
4Sight Education Ltd has appointed a Data Protection Lead (we are not relying on a statutory Article 37 DPO designation). Contact:
Under the UK GDPR, individuals have the following rights. Requests should be directed to the data controller (the school/college) in the first instance, or to us at admin@vespa.academy:
We will respond to subject access requests within one calendar month of receipt.
We implement appropriate technical and organisational measures to protect personal data, including:
eu-north-1)Primary data storage is in the EU (Supabase eu-north-1). Processing outside the UK/EEA occurs via sub-processors listed at vespa.academy/sub-processors.html (including Vercel US iad1, SendGrid, OpenAI, Anthropic for CRM/internal use, Stripe where used, and marketing-site analytics/ad tags). Transfers are protected by:
In the event of a personal data breach:
We conduct Data Protection Impact Assessments (DPIAs) when introducing new features or processing activities that are likely to result in a high risk to individuals, in accordance with Article 35 of the UK GDPR. This includes assessment of AI features (see our AI Usage Policy).
We maintain a single canonical, versioned sub-processor list at vespa.academy/sub-processors.html (current version SPL-2026.08). That page is the source of truth; the DPA Schedule 2 snapshots the same list at issue. Where optional portal AI features are used, prompt data is sent to OpenAI's API for that request only — this is sub-processor processing, not sale or sharing of data with unrelated third parties. See our AI Usage Policy.
All staff and contractors with access to personal data receive data protection training and are bound by confidentiality obligations. Access to personal data is limited to those who require it to perform their duties.
This policy is reviewed annually or when there are significant changes to our processing activities, legal requirements, or organisational structure. The “last updated” date indicates the most recent revision.
If you are unsatisfied with how we handle personal data, you may lodge a complaint with the Information Commissioner’s Office:
See our full Policies & Compliance index for all published documents.
© 2026 VESPA Academy — 4Sight Education Ltd. All rights reserved.