Last updated: August 2026 · Index version v2.0
4Sight Education Ltd (trading as VESPA Academy) publishes the following policies for schools, colleges, trusts, privacy leads and procurement teams. All documents are versioned and updated when our services or legal requirements change.
How we collect, use, and protect personal data — roles, lawful basis, rights, cookies, third parties (v2.0)
→Student-friendly version of the privacy policy
→UK GDPR compliance — controller/processor roles, DPIA, breach procedures (v2.0)
→Default retention schedule (controller-configurable), deletion and written confirmation (v2.0)
→Standard UK GDPR Article 28 DPA preview (v2.0) — issued completed on subscription confirmation
→Canonical versioned list (SPL-2026.08) — source of truth for Schedule 2
→Pre-populated DPIA assistance for schools adopting VESPA
→How student data moves through the Platform (DfE-style walkthrough)
Cyber Essentials certified (IASME-CE-060416), MFA, EU data store + Vercel US iad1 compute, incident response (v2.0)
→How AI is used (advisory only) — API sub-processors OpenAI & Anthropic; no training on school data; prompt data not sold or shared for unrelated purposes
→Business continuity and disaster recovery — RTO/RPO targets, scenario playbooks, succession and provider outage procedures
→KCSIE-aligned safeguarding and child data protection
→WCAG 2.2 commitment and accessibility feedback contact
Supply chain ethics and zero tolerance for modern slavery
→Quality objectives, controlled processes, support handling, subcontractor standards and continuous improvement (ISO 9001 substitute)
→Cloud-first operating model and environmental commitments
→Equality Act compliance — employer and service delivery commitments
→Remote working, DSE and safe working environment
© 2026 VESPA Academy — 4Sight Education Ltd. All rights reserved.