Privacy Notice
This notice informs you pursuant to Art. 13 and 14 GDPR about the processing of personal data when you use the Fornava learning and gaming platform. It describes what data we process, for what purposes, on what legal basis, for how long, to whom we disclose it, and what rights you have.
Contact: privacy@fornava.com
1. Controller
Hereinafter referred to as "Fornava" or "we".
2. Privacy Contact
For questions about privacy or to exercise your rights, you can reach us at the privacy contact address stated above. You can write to us by email or use "Your Data" in Fornava.
We generally respond without undue delay, at the latest within one month (Art. 12(3) GDPR). For complex requests, this period may be extended by up to two further months. We will inform you of this in good time.
Exercising your rights is generally free of charge. For manifestly unfounded or excessive requests, we may charge a reasonable fee or refuse the request (Art. 12(5) GDPR).
3. Data Protection Officer
No data protection officer is currently appointed, unless required by law. Whether an obligation to appoint one exists under Art. 37 GDPR in conjunction with § 38 BDSG depends, among other things, on the identity and scope of the controller and is reviewed on an ongoing basis.
If a data protection officer is appointed, their name and contact details will be added here.
4. Purposes of Processing
We process personal data in particular for the following purposes:
- Providing your account, login, and session management
- Storing your learning progress, language pairs, cards, and reviews
- Providing game content, village scenes, tools, and progress overviews
- Onboarding, placement, and adaptation of your learning path
- Chat, dialogue, and AI-supported learning features, if you have consented
- Speech input and output via our own infrastructure, if you use AI features
- Chronicle, duels, forge, and other AI-supported tools
- Processing feedback and support requests
- Processing data protection requests (Art. 15 to 22 GDPR)
- IT security, abuse prevention, and stable operation
- Optional usage analytics to improve Fornava, only if you have consented. We do not currently collect usage data.
5. Legal Bases
Depending on the activity, we rely on the following legal bases under the GDPR:
- Art. 6(1)(b) GDPR: contract or pre-contractual measures (operation of your account, storage of your learning progress, provision of core features)
- Art. 6(1)(a) GDPR: consent (AI and speech processing, optional analytics, where enabled)
- Art. 6(1)(f) GDPR: legitimate interest (see section 6)
- Art. 6(1)(c) GDPR: legal obligation, where statutory duties apply to us
You may withdraw consent given at any time with effect for the future (Art. 7(3) GDPR). Processing until withdrawal remains lawful.
6. Legitimate Interests
Where we process personal data on the basis of legitimate interests (Art. 6(1)(f) GDPR), these interests include in particular:
- IT security, integrity of your session, and abuse prevention in login operations
- Service stability and proportionate, redacted operational logs without raw content of your conversations
- Processing data protection requests with minimal verification data
- Product quality and support when you send us feedback
We balance these interests against your fundamental rights and interests. You may object at any time to processing on this basis (Art. 21(1) GDPR), where applicable. We document detailed balancing assessments internally.
7. Categories of Personal Data
Depending on your use, we process in particular:
- Account data (e.g. internal user ID, display name, email, login provider, roles)
- Language and learning context (native language, target language, cards, reviews, titles, progress, daily values)
- Game and chat content (conversation texts, dialogue inputs, relationship and scene status)
- AI context (prompts, generated texts, forge words, chronicle and duel content)
- Device-related settings and local cache on the device (where stored locally)
- Privacy settings and requests (consents, exports, deletion requests)
- Technical metadata for operation and security (e.g. redacted provider and usage metadata without raw prompts)
- Feedback and support messages when you write to us
Audio inputs are transmitted for immediate processing when you use speech features. We do not permanently store raw audio in the database afterwards.
We do not process special categories of personal data within the meaning of Art. 9 GDPR unless you provide them yourself in free-text fields.
8. Origin of Data
We obtain personal data:
- directly from you (inputs in the game, chat, forge, feedback, privacy requests)
- when logging in via Kanidm (e.g. email, display name, roles, and identity credentials)
- automatically during operation (session data, technical metadata, log data)
If we do not collect personal data from you, we inform you here. When logging in, core account data comes from the Kanidm identity service.
9. Recipients and Processors
Recipients may include:
- Fornava operations and technically authorised administrators on our infrastructure.
- Hetzner Online GmbH (cloud hosting in Germany): processor for app, database, and backups on our VPS.
- Kanidm (KANIDM/OIDC) on our own infrastructure at Hetzner (Germany, EU): login, identity credentials, and password management. Fornava does not store passwords in the database; login data remains with the Kanidm identity service.
- MS Azure Europe: provision of AI features such as conversations with villagers, personalised exercises, translations, text generation, and speech processing (speech-to-text and text-to-speech), if you have consented to the use of AI features.
- Mistral AI SAS (France): provision of AI features and text generation, if these services are used and you have consented to the use of AI features.
- Speech services on our own infrastructure (where used): short-term processing of audio. Raw audio is not permanently stored in the database.
With processors, we conclude data processing agreements under Art. 28 GDPR where legally required.
10. Transfers to Third Countries
The recipients mentioned in section 9 currently process data within the European Union or the European Economic Area (in particular Germany and France).
Transfer of personal data to third countries outside the EU/EEA is not currently intended.
If this changes (e.g. through other sub-processors, support access from third countries, cloud replication, or enabled browser speech services), we will update this notice in good time and, where required, base transfers on appropriate safeguards under Chapter V GDPR (e.g. adequacy decision or standard contractual clauses), including required transfer impact assessments.
11. Retention Period
We store personal data only as long as necessary for the stated purposes or where statutory retention obligations exist.
- Session data until expiry or logout
- Account data and learning progress for as long as your account exists
- Chat and AI content for as long as your account exists, if you use AI features
- Privacy requests, exports, and records in accordance with statutory proof obligations
- Operational logs only as long as required for security, abuse prevention, or billing
- Local device data can be reset on the device at any time
After deletion requests, we review which data must be deleted, restricted, or retained for legal reasons. Backups on our Hetzner VPS may delay deletion; we aim not to reintroduce deleted data upon restoration.
Kanidm account data (password, passkeys, identity audit) is managed separately in the identity service and subject to its own deletion or deactivation processes.
12. Device Storage, Cookies, and Local Data
In addition to server data, we use device storage:
- Web: session cookie (HttpOnly, SameSite=Lax) for your login and session management. Legal basis: Art. 6(1)(b) GDPR and § 25(2) No. 2 TTDSG (strictly necessary).
- App: secure token storage (Secure Store) for your login.
- Web and app: local device storage (browser storage or app storage) for settings, UI state, and game state. You can remove this data under "Your Data" or in the profile with "Reset device".
We currently do not use marketing cookies or third-party tracking. Optional usage analytics is not yet implemented; only your consent is stored.
Optional access to browser or operating system speech services is disabled by default and would — if ever enabled — only occur after separate legal review and an update to this notice.
13. Security of Processing
We implement appropriate technical and organisational measures under Art. 32 GDPR, including:
- encrypted transport connections (HTTPS/TLS) for login and app use
- signed HttpOnly session cookies, OIDC with state, nonce, and PKCE
- no permanent storage of OIDC access tokens in the frontend
- redacted logging for AI connections without raw prompts in logs
- short-term speech processing without permanent raw audio storage in the database
- role-based access and consent gates for AI features
Security measures are continuously adapted to the state of the art. Details on VPS hardening, encryption at rest, backup access, and incident response are documented in our record of processing activities under Art. 30 GDPR.
14. Obligation to Provide Data
Login and account data as well as data required for learning operations are necessary to use Fornava (Art. 6(1)(b) GDPR). Without this data, we cannot provide you with an account or core features.
AI features, speech processing, and optional usage analytics are voluntary. They require separate consent. Core operation without AI remains available if you do not grant these consents.
There is no legal obligation to provide data for the voluntary features.
15. Your Rights
Subject to the conditions of the GDPR, you have in particular the following rights:
- Access (Art. 15 GDPR) and a copy of your data
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR), where applicable
- Objection to processing based on legitimate interests (Art. 21(1) GDPR), where applicable
- Withdrawal of consent given (Art. 7(3) GDPR). Processing until withdrawal remains lawful.
If we have made personal data public and you are entitled to erasure, we inform other controllers where possible about your erasure request (Art. 19 GDPR), where applicable.
You can start many requests directly under "Your Data" in Fornava. Before access, export, or deletion, we may verify your identity to prevent abuse.
You are not subject to automated decision-making within the meaning of Art. 22 GDPR (see section 17).
16. Notice, Contract, and Consents
This privacy notice informs you about our processing (Art. 13/14 GDPR). Before use, you confirm that you have read it. This is not a blanket consent to all processing.
We rely on Art. 6(1)(b) GDPR (contract or pre-contractual measures) for providing your account and core features.
AI-supported features (conversations with villagers, translations, chronicle, forge, duels, speech input and output) require separate consent. Processing takes place via Mistral AI (EU/EEA) and our own speech infrastructure.
You can enable optional usage analytics separately. We currently store only your consent. Collection of analytics data is not yet implemented.
You can change consents at any time under "Your Data". Withdrawal does not affect the lawfulness of processing until withdrawal.
17. Automated Decisions and Profiling
Fornava does not make solely automated decisions within the meaning of Art. 22 GDPR that produce legal effects concerning you or similarly significantly affect you.
Learning recommendations, titles, game content, or AI-generated texts serve didactic design. They do not constitute legally binding assessments.
We currently do not carry out profiling within the meaning of Art. 4 No. 4 GDPR for advertising or evaluation purposes.
18. Data Breaches
In the event of a personal data breach, we assess the risk and act in accordance with Art. 33 and 34 GDPR.
- Notification to the supervisory authority within 72 hours if a risk exists
- Notification of data subjects if a high risk to your rights and freedoms is likely
- internal documentation of all incidents
We recommend contacting us immediately if you suspect misuse of your account.
19. Children and Young People
Fornava is not specifically directed at children. Where parental consent is required for minors under national law (in Germany, generally from age 16 for information society services), the service may not be used without such consent.
If you believe we are processing a child's data without required consent, please contact us. We will review the matter and delete or restrict processing where required by law.
20. Changes to This Notice
We may update this privacy notice when the legal situation, features, or processing change.
- The version is displayed in Fornava.
- For material changes, we will inform you appropriately (e.g. in the app or by email) before new processing takes effect, where required.
- Read the current version before using Fornava.
The controller's structured compliance documentation is maintained internally in the record of processing activities under Art. 30 GDPR.
21. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
The competent supervisory authority is the Berlin Commissioner for Data Protection and Freedom of Information [(https://www.datenschutz-berlin.de/)](https://www.datenschutz-berlin.de/).
Please contact us before lodging a complaint with a supervisory authority. We will review your request and respond. Your right to lodge a complaint with a supervisory authority remains unaffected.