GDPR Art. 28
Subprocessors
Virtual Dawn uses infrastructure and AI providers to operate SIELUNE. The exact set depends on the Customer’s Order / Deployment Profile. This is not a claim that every tenant is EU-only. Education defaults keep application chat ephemeral and non-identified; infrastructure logs may still exist at the provider for security.
| Provider | Purpose | Typical data | Possible location | Transfer basis outside EU/EEA |
|---|---|---|---|---|
| Railway | Backend, database and application infrastructure | Service data, conversation content for the active retention window, organisation accounts | EU and/or USA depending on deployment | EU–US Data Privacy Framework and/or SCCs under the applicable DPA |
| Vercel | Web service, edge/CDN and application delivery | Request metadata required to serve the portal and embeds | EU and/or USA | EU–US Data Privacy Framework and/or SCCs |
| Microsoft Azure | AI inference, Speech-to-Text, Text-to-Speech and agreed Azure cloud services | Prompt/response text; microphone audio during real-time STT where voice input is enabled; speech transcript; TTS input text and generated audio where Azure TTS is used | EU or other agreed Azure region | Microsoft DPA; SCCs / applicable adequacy mechanism where required |
| ElevenLabs | Text-to-Speech / synthetic AI character voice where configured | AI-generated response text and generated speech audio; student microphone audio is not sent to ElevenLabs in the standard SIELUNE STT flow | Provider-dependent | Applicable DPA / SCCs / DPF; optional — depends on selected character voice / Deployment Profile |
| Other separately agreed AI providers (e.g. OpenAI, Mistral) | AI inference where enabled in the Deployment Profile | Prompt and response text during inference; not used to train general models where API controls apply | Contract-specific | Defined in the Deployment Profile and this Subprocessor List |
| Resend | Transactional and service email | Business contact and invitation emails — not student chat by default | Provider-dependent (typically USA) | Applicable DPA / SCCs / DPF |
| Procountor (Visma) | Invoicing support and statutory accounting | Organisation billing and contractual records — not end-user chat | Primarily Finland / EU | Applicable provider terms and data-protection arrangements |
Where personal data is processed outside the EU/EEA, Midnight Forge Oy uses an applicable lawful transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework for participating providers, or the European Commission’s Standard Contractual Clauses (SCCs), together with supplementary safeguards where required.
Full policy: Business Privacy Policy. Terms: Business Terms. Customer-specific DPA: company@virtual-dawn.com. ICT pack: Finnish · English.