Skip to content

GDPR · organisational processing

Business Privacy Policy

Midnight Forge Oy / Virtual Dawn · Effective 16 September 2026. These documents govern organisational SIELUNE use. An owner or admin accepts the DPA in the portal (Settings → Legal). Consumer Virtual Twilight remains under /legal/privacy. Use Print / save PDF for ICT. A separately negotiated procurement DPA, if signed, prevails.

VIRTUAL DAWN / SIELUNE

BUSINESS PRIVACY POLICY

Effective date: 16 September 2026

Provider: Midnight Forge Oy, operating as Virtual Dawn

Business ID: 2504471-2

Country: Finland

Privacy contact: company@virtual-dawn.com

1. Purpose and scope

This Business Privacy Policy explains how Midnight Forge Oy / Virtual Dawn processes personal data in connection with:

  • SIELUNE;
  • SIELUNA and related creation tools;
  • Virtual Dawn business services;
  • organisation accounts;
  • business websites and portals;
  • AI training and simulation services;
  • web applications;
  • APIs;
  • Unity and XR applications;
  • customer-specific software and integrations.

Virtual Twilight and other consumer products may have separate privacy policies.

SIELUNE is a configurable platform. Different customer deployments may deliberately use different identity, retention, memory, analytics, AI-provider and hosting configurations.

This Privacy Policy therefore describes the possible processing models and explains how the configuration applicable to a particular Customer is determined.

2. Who is responsible for personal data?

Midnight Forge Oy may act in different legal roles depending on the processing activity.

Virtual Dawn as controller

Virtual Dawn generally acts as controller when it determines the purposes and means of processing, for example for:

  • Customer business contacts;
  • organisation account administration;
  • sales enquiries;
  • contractual administration;
  • billing;
  • Virtual Dawn's own website;
  • fraud and security management;
  • direct support relationships;
  • legally required business records.

Virtual Dawn as processor

Where a Customer uses SIELUNE or another Virtual Dawn Service to process information concerning its own End Users, the Customer may act as controller and Virtual Dawn may act as processor on the Customer's behalf.

Examples may include:

  • student interactions;
  • employee training;
  • Customer-specific learning results;
  • Customer user lists;
  • LMS-linked user information;
  • Customer-configured AI conversations.

Such processing is governed by the applicable Data Processing Agreement (“DPA”).

Virtual Dawn may therefore act as controller for some information and processor for other information within the same overall service relationship.

3. Privacy by configuration

SIELUNE does not require every deployment to collect the same information.

A Customer can configure a deployment according to its use case.

Possible configurations include:

Non-identified use

The End User does not need to provide:

  • name;
  • email address;
  • student number;
  • employee ID;
  • other direct identity.

The system may instead use a temporary or internal identifier such as User X.

Identified use

The Customer may enable:

  • SSO;
  • LMS integration;
  • organisation accounts;
  • email invitations;
  • user-specific reporting;
  • persistent profiles.

This may connect activity to an identified individual.

Ephemeral conversations

Conversation content exists temporarily to allow the AI to follow the ongoing discussion and can then be automatically deleted.

Persistent conversations or memory

Where long-term continuity is required, selected conversation history, derived memories, preferences or progress information may be retained across sessions.

Non-identified analytics

A Customer may receive information such as:

  • a session was started;
  • a stage was completed;
  • a goal was achieved;
  • a user failed to progress beyond a stage;
  • average completion time;
  • aggregate performance.

These analytics do not necessarily require the Customer to know the individual's identity.

Identified learning or performance results

Where explicitly configured, results may be connected to an identified End User.

The applicable Order, Deployment Profile and DPA determine the configuration used by a particular Customer.

4. “User X” and anonymous data

A deployment may represent a person only through an internal identifier such as User X without collecting their name, email address or student number.

We refer to this as non-identified use.

An internal identifier is not automatically the same thing as legally anonymised information.

Information is treated as anonymous only where it has been processed so that an individual is no longer identifiable by reasonably available means.

Where a temporary, persistent or pseudonymous identifier can still be associated with an individual, applicable data-protection law may continue to apply.

This distinction allows us to minimise identification without making inaccurate claims about technical anonymity.

5. Categories of information we may process

Depending on configuration, the Services may process the following categories.

Business and organisation information

  • name;
  • business email;
  • employer or organisation;
  • role;
  • billing information;
  • contractual information;
  • support communications.

End User identity information

Only where enabled or required:

  • name;
  • email;
  • organisation identifier;
  • SSO identifier;
  • LMS identifier;
  • username.

Conversation information

Information submitted by an End User to an AI system, including:

  • text messages;
  • instructions;
  • responses;
  • scenario choices;
  • temporary conversational context.

Persistent AI memory

Where enabled:

  • summaries of previous interactions;
  • preferences;
  • progress;
  • derived memories;
  • persistent character or coach relationships.

Simulation and learning information

Depending on the deployment:

  • stages completed;
  • goals achieved;
  • score;
  • responses;
  • completion status;
  • duration;
  • attempts;
  • evaluation results.

Customer Materials

Information supplied by Customers, including:

  • documents;
  • knowledge bases;
  • manuals;
  • course materials;
  • policies;
  • scenarios;
  • character instructions.

Technical and security information

Where generated by the relevant service or infrastructure provider:

  • IP address;
  • request metadata;
  • browser or device information;
  • authentication events;
  • error logs;
  • security events;
  • service telemetry.

Technical infrastructure information is distinct from Customer-facing learning analytics.

An IP address or similar technical identifier does not need to be shown to the Customer merely because an infrastructure provider processes it for security or network operation.

6. Ephemeral mode

SIELUNE supports ephemeral processing.

Where ephemeral mode is enabled, application-level conversation content is retained only temporarily to provide the active conversation and maintain conversational continuity.

The data is then automatically deleted according to the configured retention period.

A typical short-lived deployment may use a processing cycle of approximately 30–60 minutes.

For example, an educational simulation may be configured so that:

  1. User X starts a session;
  2. the AI temporarily remembers earlier messages in the conversation;
  3. the conversation ends;
  4. application-level conversation content is deleted approximately 30–60 minutes later;
  5. a limited non-identified event such as “simulation completed” may remain.

Ephemeral deletion of application conversation content does not necessarily mean that every technical event generated by underlying network or infrastructure providers disappears at exactly the same time.

Limited technical or security logs may have separate retention periods.

7. Persistent-memory mode

Some SIELUNE use cases depend on continuity between sessions.

Where persistent memory is enabled, the Service may retain selected information such as:

  • previous interactions;
  • progress;
  • preferences;
  • conversation summaries;
  • goals;
  • relationship or character state.

Persistent-memory processing is not enabled merely because the platform technically supports it.

Its use depends on the relevant Customer deployment and configuration.

Retention is defined by the applicable service configuration and, where applicable, Customer instructions under the DPA.

8. Identity integrations

SIELUNE may operate without user identity.

Where Customer requirements justify it, Customers may optionally enable:

  • Moodle or another LMS;
  • SSO;
  • organisation directory integration;
  • email invitations;
  • user accounts;
  • API-linked identity.

When such functionality is enabled, information necessary for the integration must be processed.

For example, sending a personalised invitation to an email address necessarily requires processing that email address.

Customers decide whether such functionality is needed for their deployment.

9. Purposes for which information is processed

Depending on the relevant role and configuration, information may be processed to:

  • provide the Services;
  • maintain AI conversation continuity;
  • provide persistent memory where enabled;
  • deliver simulations;
  • evaluate configured scenario goals;
  • provide Customer analytics;
  • provide Customer-requested user-specific results;
  • authenticate authorised users;
  • operate integrations;
  • process payments;
  • manage subscriptions;
  • provide support;
  • maintain security;
  • prevent misuse;
  • troubleshoot technical issues;
  • comply with legal requirements;
  • improve reliability and functionality using appropriate statistical or non-identifying information.

Where Virtual Dawn acts as controller, applicable legal bases may include:

Performance of a contract

Processing necessary to provide a Service requested by an individual or organisation.

Legitimate interests

For purposes such as:

  • securing the Services;
  • preventing fraud;
  • providing business support;
  • operating and improving Services;
  • managing business relationships.

We assess legitimate interests against the rights and interests of affected individuals.

For information Virtual Dawn must retain or process under applicable law, including accounting and taxation requirements.

Where a particular optional activity legally requires consent.

Where Virtual Dawn acts only as processor, the Customer is responsible for determining the applicable legal basis for the Customer's processing.

11. Customer responsibility as controller

Where the Customer acts as controller, the Customer determines:

  • why End User information is processed;
  • which features are enabled;
  • whether users are identified;
  • which analytics are required;
  • whether persistent memory is appropriate;
  • the appropriate lawful basis;
  • applicable retention requirements;
  • what information must be given to End Users.

Virtual Dawn processes Customer Personal Data according to documented Customer instructions and the applicable DPA.

12. AI processing

End User messages may be processed by AI models in order to generate responses and perform requested AI functions.

Depending on the deployment, AI processing may occur through:

  • Virtual Dawn-hosted models;
  • dedicated model infrastructure;
  • Microsoft AI services;
  • OpenAI services;
  • Mistral-based models;
  • other contracted AI providers.

The provider actually used depends on the agreed deployment configuration.

Customers requiring provider restrictions may agree those restrictions in their Deployment Profile.

13. AI model training

Virtual Dawn does not use Customer conversations or Customer Materials to train general-purpose AI models for unrelated customers without the Customer's express agreement.

We do not sell Customer conversations for AI model training.

Where supported third-party AI APIs are used, Virtual Dawn uses business/API arrangements and available settings intended to prevent Customer Content from being used for general model training.

A Customer may separately request:

  • private fine-tuning;
  • Customer-specific model development;
  • evaluation;
  • optimisation.

Such activity requires a separate agreed purpose and configuration.

14. AI-generated and derived information

AI systems may generate:

  • responses;
  • evaluations;
  • summaries;
  • scores;
  • suggested feedback;
  • derived memory;
  • categorisations.

Whether this information is retained depends on the applicable Deployment Profile.

A Customer may, for example, retain a completion score while deleting the underlying free-form conversation.

15. Automated evaluations

SIELUNE may support automated scoring or evaluation in simulations.

Unless specifically agreed for another purpose, these features are intended to support:

  • training;
  • practice;
  • formative feedback;
  • simulation;
  • educational exercises.

Customers should not use ordinary AI-generated evaluations as the sole basis for legally significant or similarly consequential decisions concerning an individual.

Deployments intended for regulated consequential decision-making require separate assessment and configuration.

16. AI transparency

Virtual Dawn designs AI interaction functionality so that users can be informed when they are interacting with an AI system where required by applicable law.

Customers must maintain legally required AI disclosures in their deployment.

Where applicable, additional transparency may be required for certain AI-generated or manipulated content, biometric categorisation or emotion-recognition systems.

17. Emotion and behavioural functionality

SIELUNE may simulate emotional behaviour within an AI character.

This does not mean Virtual Dawn automatically performs biometric emotion recognition on End Users.

A feature that infers an individual's emotional state from biometric information is materially different and may be subject to significant legal restrictions.

Such functionality is not part of a standard deployment unless specifically supported and lawfully configured.

18. Special-category and sensitive information

Free-form conversations can potentially contain sensitive information even where the Service did not request it.

This can include information concerning:

  • health;
  • religion;
  • political opinions;
  • trade-union membership;
  • sexual orientation;
  • other special-category information.

Customers should configure their deployments to avoid unnecessary collection of sensitive personal data.

Where sensitive personal data is intentionally processed, the Customer is responsible for ensuring that an appropriate legal basis and safeguards exist.

A fictional healthcare simulation should not be treated as permission to upload real patient records.

19. Children and students

SIELUNE may be used by educational institutions.

Where an institution provides the Service to students, including minors, the institution is responsible for:

  • determining the lawful basis;
  • determining authorised users;
  • providing required notices;
  • obtaining consent where consent is legally required;
  • configuring the Service appropriately.

Virtual Dawn supports privacy-minimising configurations where appropriate, including:

  • no End User account;
  • no name;
  • no email;
  • no persistent chat history;
  • limited learning analytics.

20. Analytics

The Customer may configure analytics according to its requirements.

Examples include:

  • total sessions;
  • completion rates;
  • average duration;
  • goal completion;
  • difficulty points;
  • stage progression;
  • scores.

A deployment may therefore reveal that many users fail at a particular simulation stage without revealing their names.

Identified analytics are only required where the Customer deliberately enables user-specific reporting.

21. Technical logs

Infrastructure providers may process limited technical information required to:

  • route requests;
  • operate networks;
  • investigate errors;
  • maintain security;
  • detect abuse;
  • prevent fraud.

Such information may include IP addresses or request metadata.

This does not mean that Customers automatically receive those identifiers in their SIELUNE analytics.

Retention of infrastructure logs may differ from retention of application-level conversation content.

22. Subprocessors

Virtual Dawn uses service providers to operate parts of the Services.

Depending on the deployment, these may include providers of:

  • cloud hosting;
  • databases;
  • edge delivery;
  • AI inference;
  • voice generation;
  • email delivery;
  • authentication;
  • monitoring;
  • payment processing.

A current list of material subprocessors applicable to business processing may be maintained at:

/business/legal/subprocessors

or supplied directly to the Customer.

Where Virtual Dawn acts as processor, subprocessor use is governed by the DPA.

23. International data transfers

Processing locations depend on the Customer's Deployment Profile and the providers used.

The standard managed Service should not be interpreted as automatically guaranteeing that all processing occurs only within the EU or EEA unless such restriction is expressly agreed.

Where personal data is transferred outside the EEA, Virtual Dawn uses an applicable lawful transfer mechanism where required, which may include:

  • an adequacy decision;
  • participation by the receiving organisation in the EU-U.S. Data Privacy Framework where applicable;
  • Standard Contractual Clauses;
  • another legally recognised transfer mechanism.

Customers with stricter residency requirements may request a region-restricted or dedicated deployment.

24. EU/EEA-restricted deployments

Where technically available and commercially agreed, Virtual Dawn may provide deployments with additional regional restrictions.

Examples may include:

  • EU/EEA cloud regions;
  • dedicated European infrastructure;
  • specific AI-provider restrictions;
  • Customer-provided Azure infrastructure;
  • private model hosting.

An EU/EEA-only commitment exists only where it is expressly included in the applicable Order or Deployment Profile.

25. Customer-controlled infrastructure

Some Customers may require Services or components to operate inside Customer-controlled infrastructure.

Where supported, responsibilities concerning:

  • security;
  • backups;
  • access;
  • region selection;
  • infrastructure availability

will be defined in the applicable Order or Service Description.

26. Sharing personal information

Virtual Dawn does not sell Customer personal data.

Information may be disclosed where necessary to:

  • authorised subprocessors;
  • provide the contracted Service;
  • fulfil Customer instructions;
  • comply with law;
  • protect security;
  • investigate fraud or unlawful activity;
  • complete a corporate restructuring, merger or acquisition subject to applicable legal safeguards.

Subprocessors may only process information for authorised purposes under their applicable contractual arrangements.

27. Data retention

Retention depends on the category of information and deployment configuration.

Ephemeral conversation content

Configured short-term retention.

A typical ephemeral deployment may remove application conversation content approximately 30–60 minutes after the relevant session-processing cycle.

Persistent conversation or memory

Retained according to the configuration selected by the Customer.

Identified learning results

Retained according to Customer instructions and the applicable DPA.

Non-identified or aggregated analytics

May be retained for statistical and service-management purposes where appropriate.

Organisation accounts

Retained while necessary to provide the organisation Service and for a reasonable period afterwards.

Billing and accounting records

Retained for periods required by applicable accounting and tax law.

Technical and security logs

Retained according to operational, security and infrastructure requirements and relevant provider policies.

Customer Materials

Retained while required to provide the Services and then deleted or returned according to the applicable agreement and DPA.

No universal five-year retention period applies to all SIELUNE data.

28. Deletion after termination

Where Virtual Dawn acts as processor, Customer Personal Data will be deleted or returned following termination according to:

  • Customer instructions;
  • the DPA;
  • legally required retention;
  • reasonable technical deletion cycles.

Backups may remain temporarily until overwritten according to normal backup lifecycle procedures where immediate deletion from backups is technically impractical.

29. Security

Virtual Dawn applies technical and organisational safeguards appropriate to the Service and processing risk.

These may include:

  • encrypted network connections;
  • access controls;
  • authentication;
  • role-based permissions;
  • database security;
  • secrets management;
  • software patching;
  • logging;
  • monitoring;
  • incident response;
  • provider security controls.

No information system can be guaranteed to be completely secure.

30. Personal-data incidents

Where Virtual Dawn acts as processor and becomes aware of a personal-data breach affecting Customer Personal Data, Virtual Dawn will notify the Customer without undue delay as required by the applicable DPA and provide reasonable assistance concerning the incident.

Where Virtual Dawn acts as controller, it will handle notification obligations according to applicable law.

31. Data-subject rights

Where Virtual Dawn acts as controller, individuals may have rights including:

  • access;
  • correction;
  • deletion;
  • restriction;
  • objection;
  • portability;
  • withdrawal of consent where processing is based on consent;
  • complaint to a competent data-protection authority.

Requests may be sent to:

[company@virtual-dawn.com](mailto:company@virtual-dawn.com)

Where Virtual Dawn acts as processor, requests concerning Customer-controlled End User data should normally be directed to the relevant Customer.

Virtual Dawn will reasonably assist the Customer with data-subject requests as required under the applicable DPA.

32. Cookies and browser storage

Virtual Dawn business websites and browser applications may use cookies or local storage necessary for:

  • authentication;
  • session continuity;
  • security;
  • preferences;
  • essential functionality;
  • basic service analytics.

Any non-essential cookies requiring consent will be handled through an appropriate consent mechanism where legally required.

The Business Service does not rely on behavioural advertising as a necessary part of SIELUNE.

33. Marketing

Virtual Dawn may process business-contact information to communicate about:

  • requested Services;
  • Customer relationships;
  • relevant product information;
  • events;
  • business opportunities.

Where applicable law requires consent for direct electronic marketing, the required consent will be obtained.

Recipients can opt out of marketing communications.

Operational, contractual or security communications may still be sent where necessary.

34. Confidential Customer information

Customer confidential information submitted through the Services is not made public merely because it is processed by SIELUNE.

Virtual Dawn personnel may access Customer information only where reasonably necessary for authorised purposes such as:

  • support;
  • security;
  • troubleshooting;
  • Customer-requested implementation.

Access is subject to appropriate confidentiality and access controls.

35. Aggregated and anonymised information

Virtual Dawn may create statistics from Service usage where information has been aggregated or anonymised so that individuals are no longer identifiable.

Such information may be used to:

  • understand system performance;
  • identify technical problems;
  • improve product usability;
  • plan capacity;
  • understand aggregate use.

Virtual Dawn does not treat pseudonymised personal data as anonymous merely because a person's name has been removed.

36. Changes to this Privacy Policy

This Privacy Policy may be updated to reflect:

  • product changes;
  • new deployment options;
  • new legal requirements;
  • new subprocessors;
  • security developments.

Material changes will be communicated where appropriate.

Customer-specific commitments in an active DPA or signed Order are not replaced merely by changing this general Privacy Policy.

37. Relationship with Customer agreements

Where a Customer-specific DPA, Order or Deployment Profile provides stricter or more specific rules regarding:

  • retention;
  • user identity;
  • processing location;
  • subprocessors;
  • security;
  • deletion;
  • integrations,

those customer-specific terms govern that deployment.

38. Contact

Questions concerning this Business Privacy Policy may be directed to:

Midnight Forge Oy / Virtual Dawn

Finland

Business ID 2504471-2

[company@virtual-dawn.com](mailto:company@virtual-dawn.com)

Individuals may also contact the competent data-protection supervisory authority.

In Finland, the competent supervisory authority is the Office of the Data Protection Ombudsman.

Source file: docs/legal/privacy.txt. Questions: company@virtual-dawn.com