SSpark
PricingAbout
Sign inBook a demoStart free trial

Data processing terms

Last updated: 26 August 2026 · These terms describe how Velocity EU Ltd (company number 14827391) processes personal data as a processor for each college using Spark. Each college signs an executed data processing agreement in this shape; this page is the public reference copy.

Roles and scope

For all personal data held inside a college’s Spark tenant, the college is the controller and Velocity EU is the processor under UK GDPR Article 28. We process that data only to provide the Spark service and only on the college’s documented instructions, including these terms and configuration the college applies in the product.

Details of processing

Subject matterOperation of the Spark attendance, enrichment and exams platform for the college.
DurationThe term of the college’s service agreement, plus the return/deletion period below.
Nature and purposeHosting and processing of statutory attendance registers, session check-ins, enrichment participation, exam administration (including JCQ identity checks), staff absence records, and the associated audit trail and reports.
Categories of data subjectsStudents; parents/guardians and emergency contacts; college staff.
Types of personal dataNames and college identifiers; cohort, timetable and roster membership; attendance marks and statutory codes; check-in events (time, method, device); enrichment participation; exam seating and ID-verification flags; staff absence records; account and audit metadata. Attendance and absence reasons can reveal health or safeguarding information — treated as special category data where applicable.

Our commitments as processor

  • Instructions only. We process personal data only on the college’s documented instructions, and tell the college if we believe an instruction infringes data protection law.
  • Confidentiality. Everyone we authorise to access personal data is bound by confidentiality obligations.
  • Security (Article 32). Each college’s data lives in its own physically separate database hosted in the UK (AWS London, eu-west-2); our control plane holds no student data. Access is role-restricted and enforced in the database itself (row-level security), transport is encrypted (TLS) and data is encrypted at rest, and every change to attendance records is written to a tamper-evident, hash-chained audit log whose roots are published on our transparency page.
  • Sub-processors. We use only the sub-processors listed below, under written terms no less protective than these, and give the college advance notice of any change with the right to object.
  • Data subject rights. We assist the college in responding to access, rectification, erasure and other rights requests, and route any request we receive directly to the college without undue delay.
  • Breach notification. We notify the college without undue delay after becoming aware of a personal data breach affecting its tenant, with the information the college needs for its own ICO and data-subject notifications.
  • Assistance. We provide reasonable assistance with data protection impact assessments and prior consultation relating to the service.
  • Return and deletion. At the end of the service the college chooses return (a full export of its database) or deletion; we complete it within 30 days and confirm in writing, subject only to backups that expire on a fixed schedule. The binding period is the one in the college’s executed DPA.
  • Audit. We make available the information necessary to demonstrate compliance and allow audits by the college or its appointed auditor on reasonable notice.

Sub-processors

Current sub-processors engaged in providing Spark, and what each one does:

Sub-processorServiceProcessing location
Supabase, Inc.Database hosting and authentication for each college tenantUnited Kingdom (AWS London, eu-west-2)
Vercel, Inc.Application hosting and content delivery for the consoleApplication compute for college routes runs in London (lhr1). Vercel’s global edge network also serves static marketing content from other regions; that content contains no personal data.
Resend, Inc.Transactional email delivery (invites, notifications)United States. Email is sent through Resend’s global API, so the recipient’s address and the message content — which can include a student’s name — are processed in the US under the safeguards below.

Student and staff records are held only in the UK. Where a sub-processor processes data outside the UK — email delivery above, or a sub-processor’s support operations — those transfers rest on UK-approved safeguards (the UK Addendum to the EU Standard Contractual Clauses or an adequacy decision).

Contact

DPA questions, sub-processor objections and breach reports: hello@velocity-eu.com. See also our privacy notice and terms.

← Back to home

SSpark

Modern operations for UK education. Built on the Microsoft 365 you already have.

UK data residencyGDPR · DPALondon region
© 2026 Velocity EU
PrivacyTermsDPACookiesContact