← Back to vespa.academy
VESPA Academy — Developing Student Mindsets

Data Processing Agreement

Standard terms (preview) — UK GDPR Article 28

Last updated: August 2026 · Document version v2.0 · Sub-processor list version SPL-2026.08

4Sight Education Ltd (trading as VESPA Academy)

Document ownerAntony Dennis, Director
Versionv2.0
Effective dateAugust 2026
Sub-processor list versionSPL-2026.08 (see Sub-processor list & changelog)
Review cycleAnnually or on material change
StatusStandard terms (preview) — a completed version naming your organisation is generated and sent for signature when your subscription is confirmed

This is a preview of the Data Processing Agreement we issue on subscription (UK GDPR Article 28). A completed version naming your organisation, address and effective date is generated and sent for signature when your subscription is confirmed. Schools may also present their own DPA for negotiation.

1. Parties

This Data Processing Agreement ("Agreement") is between [Customer name] of [address] (the "Controller") and 4Sight Education Ltd, Company No. 14032238, of 79 Tib Street, Manchester, M4 1LS (the "Processor"), and takes effect from [date].

2. Definitions

Terms such as "personal data", "processing", "data subject", "controller", "processor" and "personal data breach" have the meanings given in the UK GDPR and the Data Protection Act 2018.

3. Subject matter and duration

The Processor processes personal data on behalf of the Controller solely to provide the VESPA Academy service for the duration of the service agreement between the parties, and as set out in Schedule 1.

4. Processor obligations

The Processor shall:

  1. process personal data only on the Controller's documented instructions, including this Agreement, unless required by law;
  2. ensure persons authorised to process the data are under a duty of confidentiality;
  3. implement appropriate technical and organisational security measures (see Schedule 2);
  4. not engage a sub-processor without the Controller's prior general authorisation. The Controller hereby grants general written authorisation for the sub-processors listed in Schedule 2 / the published Sub-processor list (version SPL-2026.08 as at the date of this Agreement, and as snapshotted in any generated signed copy). The Processor will give the Controller at least 30 days' prior written notice of any intended addition or replacement of a sub-processor, and the Controller may object on reasonable data-protection grounds within that period. If the parties cannot resolve an objection, the Controller may terminate the affected Services without penalty for that reason;
  5. assist the Controller, taking account of the nature of processing, in responding to data subject requests and in meeting its obligations regarding security, breach notification, data protection impact assessments and consultation with the ICO;
  6. notify the Controller without undue delay on becoming aware of a personal data breach;
  7. at the Controller's choice, delete or return all personal data at the end of the service and delete existing copies, unless storage is required by law. Deletion or return will follow the default timescales in our Data Retention Policy (target within 30 days of a confirmed instruction, unless the Controller specifies otherwise), and the Processor will provide written confirmation of deletion on request;
  8. make available information necessary to demonstrate compliance and allow for and contribute to reasonable audits.

5. International transfers

Primary application data is stored in the European Union (Supabase region eu-north-1, Stockholm). Certain sub-processors process personal data outside the UK/EEA as set out in Schedule 2 (including Vercel serverless functions in the United States, SendGrid, OpenAI, Stripe where used, and marketing-site analytics/advertising tags where loaded). Where such transfers occur, the Processor relies on appropriate transfer mechanisms under UK GDPR Chapter V — principally the European Commission Standard Contractual Clauses (SCCs) as adopted for use under UK law / the UK International Data Transfer Addendum, and the sub-processor's data processing terms. The Controller's general authorisation in clause 4 includes those Schedule 2 transfers.

6. Liability and law

This Agreement is governed by the law of England and Wales. Liability is as set out in the parties' main service agreement.

7. Automated decision-making and profiling (Article 22)

VESPA scores, traffic-light indicators, national/school comparisons and AI-generated coaching or guidance text are provided as decision-support tools for staff and students. They are not solely automated decisions producing legal or similarly significant effects. The Controller must ensure that any consequential use of VESPA outputs includes appropriate human review. See also our AI Usage Policy.

Schedule 1 — Details of processing

Subject matterProvision of the VESPA Academy platform, resources, coaching tools, optional AI features and reporting
Nature and purposeHosting and processing of user accounts, questionnaire and activity data to deliver coaching, reporting and study-skills support; generation of school and national benchmarking / normative statistics as an instructed service feature (anonymous aggregates at national level; school-level analytics for that school's authorised users); optional AI-assisted coaching and learning features as described in the AI Usage Policy
DurationFor the term of the service agreement, and thereafter only as required to fulfil documented retention / erasure instructions or legal obligations
Categories of data subjectsStudents/learners; school and college staff users
Types of personal dataNames; school/college; email/usernames; date of birth (where provided by the school or MIS sync); year/cohort/tutor group; gender (where provided by the school or MIS sync); residential status (where provided); education identifiers where supplied (e.g. UPN/UCI); VESPA questionnaire responses and scores; free-text reflections, goals and coaching notes; activity and usage data; optional AI conversation content (e.g. UniGuide chat history) and AI-generated feedback; related learning artefacts (e.g. UCAS statement drafts, flashcard content where enabled)
Special category dataThe service is not designed to require special category data. Gender may be processed where the Controller supplies it (including via Wonde/MIS) for reporting and filtering. The Controller is responsible for ensuring a lawful basis (and any condition for special category data, if applicable) for instructing that processing. Ethnicity, SEN and FSM fields may exist in schema for future Controller-instructed use but are not populated by default. Incidental special category data: free-text reflections, goals, coaching notes, UniGuide chats and UCAS drafts may unintentionally contain special category information that a student or staff member chooses to write. Such data is not solicited by the Platform; it is processed only as part of the instructed coaching/learning features, access-controlled to authorised users, and subject to the same security and erasure controls as other student content.

Schedule 2 — Security measures and sub-processors

Security measures: Primary application data hosted in the EU (Supabase eu-north-1). Portal serverless API functions are delivered via Vercel in region iad1 (US East) under SCCs. Encryption in transit (HTTPS/TLS) and at rest; least-privilege access control; MFA on administrative systems; authenticated user access with SSO support; Cyber Essentials certified (IASME, certificate IASME-CE-060416); documented incident and breach response; backup and disaster-recovery arrangements per the Business Continuity & DR Plan. OpenAI organisation controls include disabled API call logging and disabled sharing of inputs/outputs for model improvement (August 2026).

Sub-processors (version SPL-2026.08 — August 2026): The canonical, versioned list (with changelog) is published at vespa.academy/sub-processors.html. The snapshot below matches that version as at the effective date of this Agreement.

Sub-processorPurposeLocation
SupabaseApplication database / data storage / authEU (Stockholm, eu-north-1)
VercelApplication hosting / serverless APIsUS (iad1) — SCCs
SendGrid (Twilio)Transactional emailUS (SCCs)
StripePayment processing (where used)EU / US (SCCs / PCI DSS)
OpenAIOptional portal AI features — API processing; not used to train models under API termsUS (SCCs)
Anthropic4Sight CRM / internal operations only (not student portal AI)US / global (SCCs)
WondeMIS data integration (where enabled by customer)UK
Microsoft Graph / Google Admin SDKDirectory sync (only when the school connects Microsoft 365 or Google Workspace)Per provider region / SCCs as applicable
Cookiebot (Usercentrics)Cookie consent management on the marketing websiteEEA / provider terms
Google Analytics (GA4)Marketing website analytics (consent-gated)US / global (SCCs / appropriate safeguards)
Meta / LinkedIn / Google Ads tagsMarketing website advertising measurement (consent-gated; not loaded in the authenticated student/staff portal)US / global (SCCs / appropriate safeguards)
WeglotOptional website/app translationPer provider terms
FL4SH / fl4sh.cardsFlashcard generation where the lite integration is enabledPer hosting arrangement

AI processing note: Optional portal AI features transmit the data needed for that feature (which may include first name, school context, questionnaire content, reflections, or multi-turn chat history for UniGuide) to OpenAI. Email addresses are not sent to OpenAI for Study Planner generation. Anthropic is used by 4Sight for CRM/internal tools, not for student portal coaching. Providers do not use API customer data to train models under applicable API business terms. Full feature list: AI Usage Policy.

Benchmarking note: National normative statistics are calculated as anonymous aggregates (no student or school identifiers in the national tables). School-level statistics remain Controller-identifiable analytics for that school's authorised users.

Signed for and on behalf of the Processor: Antony Dennis, Director, 4Sight Education Ltd — August 2026 (v2.0)

Related Documents

See our full Policies & Compliance index for all published documents.


© 2026 VESPA Academy — 4Sight Education Ltd. All rights reserved.