Last updated: June 2026
4Sight Education Ltd (trading as VESPA Academy)
| Policy owner | Antony Dennis, Director |
| Version | 2.0 |
| Effective date | August 2026 |
| Review cycle | Annually or on material change |
| Applies to | All directors, staff, contractors and associates, and all systems processing 4Sight or customer data |
This policy sets out how 4Sight Education Ltd protects the confidentiality, integrity and availability of information assets, including the personal data of students and staff processed through the VESPA Academy platform. It applies to all systems, devices and services used to deliver our services.
Primary production data for UK customers is hosted within the European Union in Supabase (eu-north-1, Stockholm). Application delivery and serverless APIs are provided by Vercel; portal functions currently run in region iad1 (US East) under Standard Contractual Clauses. We do not operate on-premise servers. Data is encrypted in transit using HTTPS/TLS, and at rest by our infrastructure providers. See the Sub-processor list for the current transfer picture.
4Sight Education Ltd is Cyber Essentials certified through the IASME Consortium (certificate IASME-CE-060416, issued 2 July 2026, valid to 2 July 2027).
Verify authenticity: https://iasme.co.uk/cyber-essentials/check-a-certificate/?cert_num=IASME-CE-060416

Our controls align with the Cyber Essentials technical control themes: firewalls, secure configuration, access control, malware protection and security update management.
Commercial insurance: Professional indemnity, public liability, employer's liability and standalone cyber liability policies are being finalised with our broker; contact admin@vespa.academy for current certificate status. (Cyber Essentials certification may include optional bundled cyber liability cover — this is supplementary to our commercial insurance arrangements.)
Company and staff devices used to access systems must be kept up to date, protected by supported operating systems, full-disk encryption where available, screen-lock and reputable malware protection.
We use a limited number of vetted sub-processors. The canonical, versioned list is published at vespa.academy/sub-processors.html and snapshotted in the DPA. Sub-processors are subject to data-processing terms consistent with UK GDPR. Customers receive at least 30 days' notice of intended changes and may object on reasonable data-protection grounds.
We retain operational and security logs for the Platform as needed to investigate incidents and support availability. For OpenAI API processing used by portal AI features, our organisation settings disable API call logging of prompts/completions for model improvement and keep OpenAI audit logging enabled for security/compliance review (evidenced August 2026). Platform application logging is separate and does not send student content to OpenAI beyond the live API request for a feature the user invokes.
Suspected or actual security incidents must be reported immediately to the Director. We investigate, contain and remediate incidents promptly. Where a personal data breach is likely to result in a risk to individuals, we notify the affected controller (the customer) without undue delay and, where applicable, support notification to the ICO within statutory timeframes.
Service resilience, backup and recovery arrangements are set out in our Business Continuity & Disaster Recovery Plan (https://vespa.academy/bcp-dr-plan.html).
The Director is responsible for information security. All staff, contractors and associates are responsible for complying with this policy and reporting concerns.
Reviewed annually, or sooner on material change.
Signed: Antony Dennis, Director, 4Sight Education Ltd — August 2026 (v2.0)
See our full Policies & Compliance index for all published documents.
© 2026 VESPA Academy — 4Sight Education Ltd. All rights reserved.