Privacy Policy - VESPA Academy
Last updated: April 2026
At VESPA Academy, we take your privacy seriously. This privacy policy explains how we collect, use, protect, and share your personal information when you use our website and services.
1. Who We Are
VESPA Academy is operated by 4Sight Education Limited. Our registered address is:
2. Information We Collect
2.1 Information You Provide
When you interact with our services, you may provide us with:
- Contact Information: Name, email address, phone number, school/college details
- Student Information: Name, date of birth, gender, year group, class group (for psychometric assessments)
- Assessment Data: Responses to VESPA psychometric questions and assessments
- Communication Data: Information from enquiry forms, emails, or other communications
2.2 Information We Collect Automatically
When you visit our website, we automatically collect:
- Technical Data: IP address (anonymized), browser type, operating system, device information
- Usage Data: Pages visited, time spent on pages, links clicked, referring websites
- Cookie Data: We use cookies to improve your experience (see our Cookie Policy section)
3. How We Use Your Information
3.1 We use your information to:
- Provide and improve our educational services and psychometric assessments
- Generate personalized student reports and "MY VESPA" activities
- Communicate with you about our services
- Analyze and improve our website and services
- Comply with legal obligations
- Protect against fraud and maintain security
Important: We never sell your personal data to third parties. All data collected through psychometric assessments remains the property of the participating school or college.
4. Legal Basis for Processing
We process your personal data based on:
- Consent: When you explicitly agree to our processing
- Contract: To fulfill our services to you or your institution
- Legitimate Interests: To improve our services and communicate effectively
- Legal Obligations: When required by law
5. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Secure, encrypted infrastructure provided by Supabase (PostgreSQL database, authentication, and storage — EU-hosted) and Vercel (website hosting and serverless API functions)
- Encryption of data in transit (TLS) and at rest
- Regular security assessments and updates
- Limited access controls, role-based permissions, and authentication requirements (including support for single sign-on via Microsoft 365 and Google Workspace)
- Regular backups and disaster recovery procedures
6. Data Retention
We retain your data only as long as necessary:
- Student Assessment Data: Shared with schools upon completion of reporting cycle
- Anonymized Research Data: Retained indefinitely for educational research (no personal identifiers)
- Contact Information: Until you request deletion or withdraw consent
- Technical Data: Typically retained for 12 months
7. Your Rights
Under data protection law, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a structured format
- Object: Object to certain types of processing
- Restrict: Request limitation of processing
To exercise any of these rights, please contact us at admin@vespa.academy
8. Cookies
We use cookies to:
- Remember your preferences
- Understand how you use our website
- Improve your experience
You can control cookies through your browser settings. Disabling cookies may affect some website functionality.
9. Third-Party Services
We use carefully selected third-party services, each bound by data protection agreements:
- Supabase: PostgreSQL database, user authentication, and file storage (EU-hosted region)
- Vercel: Website hosting and serverless API functions
- SendGrid (Twilio): Transactional email delivery (welcome emails, notifications, reports)
- Google Analytics: Anonymised website analytics
- Stripe: Payment processing (PCI DSS Level 1 compliant — we do not store card details)
- Microsoft Graph API / Google Admin SDK: Directory synchronisation for student and staff imports (only activated when your school connects Microsoft 365 or Google Workspace)
10. International Transfers
Your primary data is stored in Supabase's EU-hosted region. Some processing may occur outside the UK/EEA
through our hosting and email providers (Vercel, SendGrid). We ensure appropriate safeguards are in place,
including standard contractual clauses approved by the ICO and the European Commission.
11. Children's Privacy
Our psychometric assessments may involve students under 18. We work exclusively through educational institutions who provide appropriate consent and oversight.
12. Data Processing Relationship
Where we process personal data on behalf of an educational organisation (for example, student questionnaire responses and assessment data),
the educational organisation is the data controller and 4Sight Education Ltd acts as the data processor.
- We process personal data only in accordance with the instructions of the educational organisation and applicable data protection law.
- A Data Processing Agreement (DPA) is available on request — contact admin@vespa.academy.
- We do not use student data for any purpose other than providing the Services, unless anonymised for educational research (with no personal identifiers).
13. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:
- Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, where required by law.
- Notify the affected educational organisation without undue delay, providing details of the breach, the data affected, and the measures taken or proposed to address it.
- Document all breaches (including those that do not require notification) as part of our internal records.
14. Changes to This Policy
We may update this policy periodically. Material changes will be notified via our website or email.
15. Contact Us
For questions about this privacy policy or your data:
16. Complaints
If you're unsatisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
© 2026 VESPA Academy 2.0 - 4Sight Education Ltd. All rights reserved.
Built by 4Sight Education
· Web development by 4site.dev