Data Processing Agreement

For UK schools and Multi-Academy Trusts · Updated January 2026

1. Scope and parties

This DPA is entered into between the School (Controller) and Veto Swarm Intelligence Ltd, trading as Supernova Science (Processor).

2. Subject matter of processing

Student performance data and assessment data generated through use of the Supernova Science platform.

3. Duration of processing

The duration of the School's active subscription, plus 12 months of secure retention.

4. Nature and purpose

Educational analytics, AI marking, and progress reporting to authorised school staff and (where permitted) parents.

5. Types of personal data

Names, school email addresses, assessment answers, mastery scores, and platform usage metadata.

6. Categories of data subjects

Pupils aged 11-18, teachers, and school administrators.

7. UK GDPR obligations

The Processor's obligations under Article 28 of the UK GDPR are met in full, including confidentiality, security, sub-processor controls, audit rights, and assistance with data subject requests.

8. Data residency

All personal data is processed and stored within the UK/EU on Supabase EU region infrastructure.

9. Sub-processors

Anthropic (AI grading; data not retained for training) and Supabase (secure storage).

10. Security measures

Row-Level Security, HTTPS, encryption at rest and in transit, and MFA for staff accounts.

11. Breach notification

Personal data breaches will be reported to the School's DPO within 72 hours of the Processor becoming aware.

12. Letter of Authority

By executing this DPA, the School confirms it is authorised to submit pupil data and has met its safeguarding and privacy obligations toward data subjects.