Skip to content

GDPR Art. 28 · clickwrap + PDF

Data Processing Agreement

Midnight Forge Oy / Virtual Dawn · Effective 16 September 2026. These documents govern organisational SIELUNE use. An owner or admin accepts the DPA in the portal (Settings → Legal). Consumer Virtual Twilight remains under /legal/privacy. Use Print / save PDF for ICT. A separately negotiated procurement DPA, if signed, prevails.

VIRTUAL DAWN / SIELUNE

DATA PROCESSING AGREEMENT (DPA)

Version: 2026-09-16

Provider (Processor): Midnight Forge Oy, operating as Virtual Dawn

Business ID 2504471-2 · Finland

Contact: company@virtual-dawn.com

This Data Processing Agreement (“DPA”) applies when a Customer uses SIELUNE or related Virtual Dawn business services to process personal data of its End Users. It forms part of the Business Terms at /business/legal/terms.

An authorised representative may accept this DPA electronically in the SIELUNE portal. That clickwrap acceptance is intended to constitute the Customer’s agreement to this DPA for the organisation.

1. Roles

The Customer is the controller for End User personal data processed in its organisation workspace (students, staff, invited users, Customer-configured conversations and learning results).

Virtual Dawn is the processor for that End User data (GDPR Art. 28).

Virtual Dawn remains controller for its own business records (organisation accounts, billing, security, support contacts).

2. Subject-matter and duration

Virtual Dawn processes Customer Personal Data only to provide the contracted Services, for the duration of the Customer’s organisation account, and thereafter only as required for deletion cycles, backups or law.

3. Nature of processing

Processing may include hosting, storage, transmission, AI inference, analytics configured by the Customer, support access, security logging and deletion.

Default education / ephemeral deployments keep application-level chat only for conversational continuity and delete it on a short cycle (typically about 30–60 minutes / ~1 hour). Persistent memory, named identity, LMS/SSO or email invitations run only when the Customer enables them.

4. Types of personal data

Depending on Customer configuration:

  • non-identified session labels (for example “User X”);
  • conversation content for the active retention window;
  • optional name, email, SSO/LMS identifiers;
  • simulation scores and stage progress;
  • organisation administrator account data;
  • technical metadata processed by infrastructure providers (which need not appear in Customer analytics).

5. Data subjects

End Users authorised by the Customer, including learners, employees, invitees and administrators.

6. Instructions

Virtual Dawn processes Customer Personal Data only on documented Customer instructions, including this DPA, the Order, the Deployment Profile and settings the Customer configures in the portal, unless Union or Member State law requires otherwise.

7. Confidentiality

Persons authorised to process Customer Personal Data are bound by confidentiality.

8. Security

Virtual Dawn implements appropriate technical and organisational measures as described in the Business Privacy Policy, including encryption in transit, access controls and role-based portal permissions. No internet service is perfectly secure.

9. Subprocessors

The Customer authorises Virtual Dawn to use subprocessors needed to operate the Service. The current public list is at /business/legal/subprocessors.

Material changes will be reflected on that page. Customers with stricter provider or region limits must record those limits in an Order or Deployment Profile.

Subprocessors are bound by data-protection obligations equivalent in substance to this DPA.

10. International transfers

The standard managed Service is not automatically EU/EEA-only. Where personal data is transferred outside the EEA, Virtual Dawn uses a lawful mechanism (adequacy, SCCs, and/or Data Privacy Framework as applicable).

EU-region, dedicated or Customer-controlled Azure deployments apply only if expressly agreed.

11. Assistance

Virtual Dawn will reasonably assist the Customer with:

  • data-subject requests;
  • security and DPIA queries proportionate to the Service;
  • personal-data breach notification without undue delay after Virtual Dawn becomes aware of a breach affecting Customer Personal Data.

End User requests concerning Customer-controlled data should normally go to the Customer first.

12. Deletion and return

After the Services end, Virtual Dawn will delete or return Customer Personal Data according to portal/export tools, this DPA and legally required retention. Backups may persist until overwritten in the normal backup cycle.

Application ephemeral chat is deleted on the configured short cycle and is not retained as a long-term student file.

13. Audits

Upon reasonable written request, Virtual Dawn will provide information reasonably necessary to demonstrate compliance with this DPA (including this public description, subprocessor list and security summary). Formal on-site audits may be agreed where proportionate.

14. Model training

Virtual Dawn does not use Customer conversations or Customer Materials to train general-purpose or third-party foundation models for unrelated customers without the Customer’s express agreement.

15. Customer responsibilities

The Customer is responsible for:

  • lawful basis and End User notices;
  • deciding whether users are identified;
  • configuring retention, integrations and analytics;
  • not using ordinary SIELUNE scores as the sole basis for high-risk decisions unless separately agreed;
  • ensuring the person who accepts this DPA is authorised to bind the Customer.

16. Precedence

If a separately signed procurement DPA or Order is stricter, that document prevails for that Customer. This portal DPA is the standard processor terms for self-serve and typical institutional use.

17. Governing law

Finnish law, unless the Order states otherwise.

Midnight Forge Oy / Virtual Dawn

company@virtual-dawn.com

Source file: docs/legal/DPA.txt. Questions: company@virtual-dawn.com