For IT · Procurement · PDF
SIELUNE — technical service description (ICT)
Midnight Forge Oy / Virtual Dawn · Effective 16 September 2026. These documents govern organisational SIELUNE use. An owner or admin accepts the DPA in the portal (Settings → Legal). Consumer Virtual Twilight remains under /legal/privacy. Use Print / save PDF for ICT. A separately negotiated procurement DPA, if signed, prevails.
SIELUNE — Technical Service Description for ICT Review
Document type: Technical service description (procurement & ICT)
Service: SIELUNE · Virtual Dawn / Midnight Forge Oy
Version: 1.4
Date: 18 September 2026
Language: English
Purpose: General overview of service technology, data handling, hosting and subprocessors for customer ICT and information-security review.
PDF: Open the page and choose *Print / Save as PDF*:
https://www.virtualtwilight.app/business/legal/ict-en
Finnish version: /business/legal/ict
Provider: Midnight Forge Oy (Virtual Dawn) · Business ID 2504471-2 · Finland
Contact: company@virtual-dawn.com
Binding legal documents
- Terms:
/business/legal/terms - Privacy Policy:
/business/legal/privacy - Data Processing Agreement (DPA):
/business/legal/dpa - Subprocessors:
/business/legal/subprocessors
This technical description complements the documents above. It does not replace the DPA, Privacy Policy, Order or other agreed contractual terms.
1. Service overview
SIELUNE is Virtual Dawn's organisational platform for AI-assisted interaction, simulation, practice and guided dialogue.
Typical use cases include:
- conversation and communication exercises,
- simulated customers, patients, employees or other roles,
- coaching and guided practice,
- interactive scenarios,
- organisational AI companions and assistants.
Typical delivery consists of:
- browser-based web application,
- Business Portal and embeddable chat,
- organisation workspace for accounts, projects and AI characters,
- optional API, LMS, SSO, LTI or XR integrations.
Integrations are not required for normal use.
SIELUNE can be configured for different levels of identity and persistence. A customer may use the service without named end-user accounts, or may enable identified users, organisational authentication, persistent history or memory where required.
2. Default service model: no named identity + ephemeral conversation
For normal training and simulation use, the default configuration does not require the end user to provide a name, email address, student number or other direct identifier.
| Topic | Default |
|---|---|
| User identification | No named identity required |
| Session | Temporary session |
| Application identifier | Temporary session ID / “User X” |
| Conversation history | Ephemeral |
| Individual long-term memory | Off |
| SSO / LMS identity | Off |
| Individual learning record | Off unless configured |
| Aggregated progress | May be enabled without attaching it to a named person |
A temporary technical or pseudonymous session identifier is used so that the service can maintain a coherent conversation during the active session.
Under the default ephemeral configuration, conversational content is retained only for the short period required to operate the session and provide conversational continuity.
Application-level conversational data is normally removed automatically after the configured short retention window, typically approximately 30–60 minutes after the active session.
A lasting user-specific conversation history or person-bound AI memory is not created by default.
Named identity, persistent memory, individual result tracking, SSO or LMS integration are enabled only where the customer selects those functions.
3. High-level architecture
Typical managed-service architecture:
Browser / customer embed
↓
Vercel
Web application / edge delivery
↓
Railway
API / realtime communication / background services
├── PostgreSQL
├── Redis / cache
└── AI inference
└── Microsoft Azure AI and/or
other contractually selected model provider
Main components:
Frontend
Next.js-based web applications, portals and embedded user interfaces.
Backend
Application API, realtime communication, service logic and background processing.
Database
PostgreSQL is used for organisation, configuration and other application data requiring persistence.
Cache / transient state
Redis may be used for temporary caching, session-related state and performance optimisation. It is not intended as the primary long-term store for end-user conversational history.
AI inference
AI models are accessed through controlled API-based inference. Application logic, permissions, organisational configuration and SIELUNE-specific functionality remain within the SIELUNE service.
4. Integrations
External customer-system integrations are optional.
| Integration | Default |
|---|---|
| Moodle / LMS | Off |
| SSO | Off |
| Customer-site embed | Available |
| API integration | Available separately |
| LTI | Only if configured |
| Grade / result passback | Only if configured |
| XR / Unity integration | Available separately |
A normal SIELUNE deployment does not require access to the customer's internal systems.
Customer systems do not automatically receive SIELUNE data unless an integration has been specifically enabled and configured.
5. Cloud infrastructure, AI and processing location
SIELUNE is normally delivered as a managed cloud service.
Typical service providers include:
| Layer | Provider | Purpose |
|---|---|---|
| Application backend | Railway | API and application services |
| Database | Railway / PostgreSQL | Application and organisation data |
| Web application / edge | Vercel | Web portals and embedded interfaces |
| AI inference | Microsoft Azure AI | AI inference where selected |
| Optional AI routes | Contractually selected provider | Only where applicable to the deployment |
Geographic processing
The standard managed service may use infrastructure located in the EU/EEA and/or the United States depending on the current production architecture, capacity, availability and selected service components. A guaranteed EU/EEA-only processing environment can be agreed separately as a customer-specific Deployment Profile.
Such a deployment may specify, for example:
- EU-region backend services,
- EU-region databases,
- EU-region or EU Data Zone AI services where available,
- restrictions on optional AI providers,
- agreed data-transfer requirements,
- customer-specific infrastructure requirements.
A guaranteed EU-residency environment is agreed separately in the Order, Statement of Work or Deployment Profile and may affect architecture, availability and commercial terms.
Where personal data is transferred internationally, the applicable DPA and legally recognised transfer mechanisms apply.
Infrastructure providers may maintain operational, security, connection and diagnostic logs required to run and protect their services. These technical infrastructure logs are separate from the application-level conversational history visible through SIELUNE.
6. Data processed
Default ephemeral use
Depending on the use case, the service may process:
- text entered into the active conversation,
- temporary session identifier,
- AI-generated responses,
- technical information required to provide the service,
- optional progress information relating to the session.
Under the default configuration, the service does not require:
- end-user name,
- end-user email address,
- student number,
- employee number,
- LMS identity,
- SSO identity,
- persistent user-specific conversation history,
- persistent user-specific AI memory.
Organisation administration
For the contractual customer relationship, SIELUNE may process:
- organisation name,
- administrator and contact names,
- work email addresses,
- organisation account information,
- service configuration,
- support communications,
- invoicing and contractual information.
Optional customer-enabled functions
Additional data may be processed when the customer enables functions such as:
- named user accounts,
- SSO,
- LMS integration,
- individual training results,
- persistent conversation history,
- persistent AI memory,
- LTI or grade passback,
- customer-system integrations.
The exact processing depends on the deployment selected by the customer.
7. Retention
Retention depends on the type of data and the selected deployment.
| Data category | Typical default |
|---|---|
| Ephemeral conversation | Approximately 30–60 minutes after active use |
| Temporary session identifier | Follows the ephemeral session lifecycle |
| Persistent user history | Not created by default |
| Persistent AI memory | Off by default |
| Aggregated service analytics | May be retained for service and content-quality monitoring |
| Organisation account | Contract term and necessary post-contract administration |
| Support information | As required for support and contractual purposes |
| Accounting / billing records | According to applicable legal requirements |
| Infrastructure / security logs | According to the relevant infrastructure provider's operational retention policies |
Where the customer enables persistent history, named users, individual learning records or memory, separate retention settings may apply.
Deletion from the active application database does not necessarily mean simultaneous deletion from infrastructure-level backups or security logs. Backup and infrastructure retention follow the applicable provider and service configuration.
8. Access and tenant separation
| Party | Access |
|---|---|
| Organisation administrators | Their organisation's authorised settings, projects and AI characters |
| End user | Their own active session and functions made available by the organisation |
| Virtual Dawn support | Limited need-based access for service operation and support |
| Infrastructure subprocessors | Processing technically necessary to provide the service |
Access is controlled according to roles and organisational boundaries.
Customer organisations are logically separated within the service.
Administrative access is limited to authorised functions.
Support access is used only where required for troubleshooting, maintenance, security or customer support.
Customer systems are not automatically connected to SIELUNE and do not automatically receive SIELUNE data.
9. Security
SIELUNE uses technical and organisational controls appropriate to a managed cloud application.
These include, as applicable:
- encrypted HTTPS / WSS communication,
- encrypted cloud storage and database infrastructure where provided by the underlying cloud platform,
- organisation- and role-based access control,
- separation of organisation and project data,
- restricted administrative access,
- secret and credential management,
- provider-level infrastructure monitoring,
- application health monitoring,
- security and operational logging,
- controlled API access,
- backup and recovery mechanisms provided by the selected infrastructure,
- software dependency and platform maintenance,
- short-lived conversational storage in the default ephemeral configuration,
- incident handling and notification according to the DPA.
The default ephemeral architecture reduces the amount of conversational information retained by the service over time.
Customer conversations are not intentionally used by Virtual Dawn to train a general-purpose AI model.
For API-based enterprise AI services, model-provider handling is governed by the applicable provider agreement and the SIELUNE deployment configuration.
Additional security, network, residency or customer-cloud requirements can be agreed as part of a customer-specific Deployment Profile.
10. GDPR roles
The parties' GDPR roles depend on the context in which personal data is processed.
| Processing | Role |
|---|---|
| End-user data processed for the customer's SIELUNE deployment | Customer organisation normally acts as Controller |
| Processing performed by Virtual Dawn on the customer's instructions | Midnight Forge Oy / Virtual Dawn acts as Processor |
| Virtual Dawn's own customer administration, billing and contractual contacts | Midnight Forge Oy acts as Controller |
Where Virtual Dawn acts as Processor, processing is governed by the SIELUNE Data Processing Agreement in accordance with GDPR Article 28.
The standard DPA is available through the service and can be printed or retained by the customer.
Where a separately negotiated procurement DPA has been executed between the parties, the negotiated agreement prevails to the extent specified in that agreement.
11. Subprocessors
SIELUNE uses infrastructure and service providers required to operate the managed service.
The current authoritative subprocessor list is maintained at:
/business/legal/subprocessors
Key technical service providers used in the standard managed service:
| Service provider | Purpose | Possible processing location | Basis for transfer outside the EU/EEA |
|---|---|---|---|
| Railway | Backend, database and application infrastructure | EU and/or USA depending on deployment | EU–US Data Privacy Framework and/or SCCs under the applicable DPA |
| Vercel | Web service, edge/CDN and application delivery | EU and/or USA | EU–US Data Privacy Framework and/or SCCs |
| Microsoft Azure | AI inference and agreed cloud services | EU or other agreed Azure region | Microsoft DPA; SCCs / applicable adequacy mechanism where required |
| Other separately agreed AI providers (e.g. OpenAI, Mistral) | AI inference | Contract-specific | Defined in the Deployment Profile and Subprocessor List |
| Resend | Transactional and service email | Provider-dependent (typically USA) | Applicable DPA / SCCs / DPF |
| Procountor (Visma) | Invoicing support and statutory accounting | Primarily Finland / EU | Applicable provider terms and data-protection arrangements |
Optional AI providers are not automatically enabled for customer deployments where their use has been restricted by the agreed Deployment Profile.
The exact providers used can depend on the deployment configuration and customer requirements. End-user conversational content from ephemeral education defaults is not sent to email or accounting systems.
International transfers
Where personal data is processed outside the EU/EEA, Midnight Forge Oy uses an applicable lawful transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework for participating providers, or the European Commission’s Standard Contractual Clauses (SCCs), together with supplementary safeguards where required. The currently applicable subprocessors are maintained in the SIELUNE Subprocessor List.
12. Customer-specific Deployment Profiles
SIELUNE is designed so that ICT, data-protection and infrastructure requirements can be defined separately from the application functionality.
A customer-specific Deployment Profile may specify requirements including:
- EU/EEA-only processing,
- selected hosting region,
- selected AI provider,
- customer Azure environment,
- disabled optional AI providers,
- authentication requirements,
- SSO,
- retention rules,
- persistent or ephemeral use,
- integration restrictions,
- logging requirements,
- API access,
- LMS / LTI integration,
- customer-specific security requirements.
Requirements that differ from the standard managed-service configuration must be agreed in the Order, Statement of Work or other applicable contractual document.
13. ICT document pack
The current ICT and legal materials are available through the SIELUNE Business Portal.
- Technical Service Description —
/business/legal/ict-en - Finnish Technical Service Description —
/business/legal/ict - Privacy Policy —
/business/legal/privacy - Data Processing Agreement —
/business/legal/dpa - Subprocessors —
/business/legal/subprocessors - Terms —
/business/legal/terms
In the Business Portal:
Settings → Legal, privacy & DPA → For IT
14. Contact
Midnight Forge Oy / Virtual Dawn
Business ID 2504471-2
Finland
Email: company@virtual-dawn.com
For customer-specific ICT, security, integration or data-residency requirements, please contact Virtual Dawn before deployment so that the applicable Deployment Profile can be agreed.
*End of document.*
Source file: docs/legal/SIELUNE_ICT_service_description_en.md. Questions: company@virtual-dawn.com