Data Processing Agreement
For UK schools and Multi-Academy Trusts · Updated January 2026
1. Scope and parties
This DPA is entered into between the School (Controller) and Veto Swarm Intelligence Ltd, trading as Supernova Science (Processor).
2. Subject matter of processing
Student performance data and assessment data generated through use of the Supernova Science platform.
3. Duration of processing
The duration of the School's active subscription, plus 12 months of secure retention.
4. Nature and purpose
Educational analytics, AI marking, and progress reporting to authorised school staff and (where permitted) parents.
5. Types of personal data
Names, school email addresses, assessment answers, mastery scores, and platform usage metadata.
6. Categories of data subjects
Pupils aged 11-18, teachers, and school administrators.
7. UK GDPR obligations
The Processor's obligations under Article 28 of the UK GDPR are met in full, including confidentiality, security, sub-processor controls, audit rights, and assistance with data subject requests.
8. Data residency
All personal data is processed and stored within the UK/EU on Supabase EU region infrastructure.
9. Sub-processors
Anthropic (AI grading; data not retained for training) and Supabase (secure storage).
10. Security measures
Row-Level Security, HTTPS, encryption at rest and in transit, and MFA for staff accounts.
11. Breach notification
Personal data breaches will be reported to the School's DPO within 72 hours of the Processor becoming aware.
12. Letter of Authority
By executing this DPA, the School confirms it is authorised to submit pupil data and has met its safeguarding and privacy obligations toward data subjects.