Privacy Policy - VESPA Academy
Last updated: August 2026 · Version v2.0
At VESPA Academy, we take your privacy seriously. This privacy policy explains how we collect, use, protect, and share your personal information when you use our website and services.
1. Who We Are
VESPA Academy is operated by 4Sight Education Limited. Our registered office address (Companies House) is:
2. Information We Collect
2.1 Information You Provide
When you interact with our services, you may provide us with:
- Contact Information: Name, email address, phone number, school/college details
- Student Information: Name, date of birth, gender, year group, class group (for psychometric assessments)
- Assessment Data: Responses to VESPA psychometric questions and assessments
- Communication Data: Information from enquiry forms, emails, or other communications
2.2 Information We Collect Automatically
When you visit our website, we automatically collect:
- Technical Data: IP address (anonymized), browser type, operating system, device information
- Usage Data: Pages visited, time spent on pages, links clicked, referring websites
- Cookie Data: We use cookies and similar technologies as described in section 8 (Cookies)
3. How We Use Your Information
3.1 We use your information to:
- Provide and improve our educational services and psychometric assessments
- Generate personalized student reports and "MY VESPA" activities
- Communicate with you about our services
- Analyze and improve our website and services
- Comply with legal obligations
- Protect against fraud and maintain security
Important: We never sell your personal data to third parties. For student assessment and platform data, the educational organisation is the
data controller and 4Sight Education Ltd is the
data processor — we process that data only on the school's instructions (see our
Data Processing Agreement).
4. Legal Basis for Processing
4.1 Where we act as processor (student / staff platform data)
The school, college or trust (the controller) determines the lawful basis for processing student and staff platform data — commonly public task and/or contract in an education setting. We process that data only on the controller's documented instructions under our DPA.
4.2 Where we act as controller
For our own business activities we rely on:
- Contract: Billing, account administration and delivering subscribed services to the organisation
- Legitimate interests: Responding to enquiries, B2B marketing to prospective schools (with opt-out), service improvement analytics on our marketing site where appropriate
- Consent: Where we ask for it (for example certain marketing cookies / advertising tags on the marketing website)
- Legal obligation: Where required by law
5. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Secure, encrypted infrastructure provided by Supabase (PostgreSQL database, authentication, and storage — EU
eu-north-1) and Vercel (website hosting and serverless API functions — portal region iad1 US, under SCCs)
- Encryption of data in transit (TLS) and at rest
- Regular security assessments and updates
- Limited access controls, role-based permissions, and authentication requirements (including support for single sign-on via Microsoft 365 and Google Workspace)
- Regular backups and disaster recovery procedures
6. Data Retention
We retain your data only as long as necessary for the purposes described in this policy and our customer agreements:
- Student service data: Retained while the student is enrolled/active on the Platform, then deleted or returned in line with the school's instructions and our Data Retention Policy
- National benchmarking aggregates: Anonymous statistical aggregates (no student or school identifiers) used as an instructed service feature for normative comparison — not open-ended “research” reuse of identifiable student records
- Contact Information: Until you request deletion or withdraw consent (marketing/enquiries)
- Technical Data: Typically retained for 12 months
7. Your Rights
Under data protection law, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a structured format
- Object: Object to certain types of processing
- Restrict: Request limitation of processing
To exercise any of these rights, please contact us at admin@vespa.academy
8. Cookies
On our marketing website (vespa.academy), we use Cookiebot (Usercentrics) to manage cookie consent. Depending on your choices, that may allow:
- Necessary cookies — required for the site to work (always active)
- Preferences / statistics — for example Google Analytics (GA4), where you consent
- Marketing — consent-gated advertising tags (Meta, LinkedIn, Google Ads), where you consent
You can change or withdraw cookie consent via the Cookiebot banner / preference centre on the marketing site, and you can also control cookies through your browser settings. Disabling some cookies may affect website functionality.
The authenticated student/staff portal (app.vespa.academy) does not load Cookiebot, Google Analytics, or advertising tags. Portal cookies are limited to what is needed for login, session security, and core product features.
Cookiebot and related marketing tools are listed in our Sub-processor list.
9. Third-Party Services
We use carefully selected third-party services. The canonical, versioned list is our Sub-processor list (SPL-2026.08). In summary:
- Supabase: PostgreSQL database, authentication, and storage (EU
eu-north-1)
- Vercel: Website hosting and serverless API functions (portal functions: US
iad1)
- SendGrid (Twilio): Transactional email
- Stripe: Payment processing (PCI DSS Level 1 — we do not store card details)
- OpenAI: Optional portal AI features (see AI Usage Policy)
- Anthropic: 4Sight CRM / internal operations only
- Wonde: MIS integration where enabled by the school
- Microsoft Graph / Google Admin SDK: Directory sync when the school connects Microsoft 365 or Google Workspace
- Cookiebot, Google Analytics (GA4), and consent-gated advertising tags (Meta, LinkedIn, Google Ads): Marketing website only — not loaded in the authenticated student/staff portal
- Weglot: Optional translation
- FL4SH: Flashcard generation where enabled
10. International Transfers
Primary application data is stored in Supabase's EU region (eu-north-1). Processing outside the UK/EEA occurs
through sub-processors listed in our Sub-processor list, including Vercel (US iad1),
SendGrid, OpenAI, Anthropic for CRM/internal use (US / global under SCCs), Stripe where used, and — on the marketing
website only — Google Analytics and consent-gated advertising tags. We rely on appropriate safeguards under UK GDPR
Chapter V, including Standard Contractual Clauses / the UK International Data Transfer Addendum and sub-processor DPAs.
11. Children's Privacy
Our psychometric assessments may involve students under 18. We work exclusively through educational institutions, which determine the lawful basis for that processing (typically public task and/or contract in an education setting) and provide appropriate oversight. We process student data as their processor under our DPA.
12. Data Processing Relationship
Where we process personal data on behalf of an educational organisation (for example, student questionnaire responses and assessment data),
the educational organisation is the data controller and 4Sight Education Ltd acts as the data processor.
- We process personal data only in accordance with the instructions of the educational organisation and applicable data protection law.
- Our standard Data Processing Agreement (DPA v2.0) is incorporated by reference into our Terms & Conditions and any quote, estimate, trial or subscription confirmation. A completed DPA naming your organisation is issued when your subscription or trial is confirmed. A preview is at vespa.academy/data-processing-agreement.html. Countersignature is optional; acceptance is by subscription/trial/continued use.
- We process student data to provide the Services under the school's instructions, including coaching, reporting, optional AI features, and national benchmarking aggregates as described in our DPA.
- Optional AI features are described in our AI Usage Policy (updated August 2026).
13. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:
- Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, where required by law.
- Notify the affected educational organisation without undue delay, providing details of the breach, the data affected, and the measures taken or proposed to address it.
- Document all breaches (including those that do not require notification) as part of our internal records.
14. Changes to This Policy
We may update this policy periodically. Material changes will be notified via our website or email.
15. Contact Us
For questions about this privacy policy or your data:
16. Complaints
If you're unsatisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
© 2026 VESPA Academy — 4Sight Education Ltd. All rights reserved.
Built by 4Sight Education
· Web development by 4site.dev