OMR Reviews
find out more"I have finally found a tool that allows me to embed videos on my website in compliance with GDPR and without additional cookies."
Ignite is a European B2B video hosting platform. Most of what a data-protection or IT security assessment would flag on a video provider — tracking cookies, cross-border data transfers, sub-processor spread, third-party scripts on the player — is closed at the architecture level rather than through configuration. What follows is the compressed argument, structured the way an assessment usually runs. The full documentation is available through the Security & Compliance hub.

A standard assessment of a video hosting vendor runs through: data flows, cookie behaviour, hosting location, sub-processor list, contractual basis, technical and organisational measures, and any third-party scripts loaded by the embedded player. On most consumer or US-adjacent video platforms, that pass surfaces items that require write-up or cannot be closed without additional controls.
The four sections below cover what most of that assessment addresses, with the architectural reason each item is resolved rather than mitigated.
Ignite sets no cookies of any kind during video playback: not essential, not functional, not measurement. No personal data of website visitors is processed. IP addresses are not captured at the infrastructure level (not anonymised, not briefly stored, not collected, ...). No fingerprinting, no cross-site identifiers, no third-party scripts loaded by the player. No consent entry is required in the CMP.
The documents required for a standard vendor assessment are available on request through the Security & Compliance hub: Data Processing Agreement, sub-processor list with 30-day change-notice terms, technical and organisational measures covering confidentiality, integrity, availability and separation, data-centre certifications.
The assessment file can proceed in parallel with the technical evaluation; nothing is gated behind a sales cycle.

Access control is applied without custom development: password protection at the video level, domain restriction at the embed level, and CDN Security (Enterprise plans) that gates every file on the CDN through time-limited signed cookies. Standard use cases like public embed, partner-only content, internal-only recording, restricted preview are ready to use.
Ignite supports SSO on enterprise plans. Video delivery can route through the customer's own Web Application Firewall or through Ignite's. Video, thumbnails, subtitles, and the player itself can be served under a customer subdomain, making the video a first-party resource in the browser network tab.

The visitor's browser requests the video player and video files from the customer's dedicated Ignite storage. No cookies are set. No third-party tracking scripts are loaded by the player. No middleware involved. Where you have enabled first-party domain delivery, the request goes to your own subdomain; the video is a first-party resource in the browser network tab.

The player streams the video over HLS with adaptive bitrate from European & Global CDN nodes. The visitor's IP is not stored, hashed, logged at all, or forwarded. Aggregated playback events (play, pause, completion) are recorded for per-video analytics only; no individual visitor is identifiable from this data.

The following do not occur at any point during playback: cookie set on the visitor's browser; personal data stored in Ignite's systems; fingerprinting tricks via canvas, audio, font, or otherwise; transfer of any personal data outside European infrastructure; cross-site identifier shared across visits;
Most video hosting providers describe themselves as GDPR-compliant, which is true. The claim is generally accurate as stated: with proper consent, the platform can be operated within the GDPR framework. The obligations that follow, cookie banner entry, consent flow, CMP configuration, legal review of the consent UI in the applicable jurisdiction, are yours to do, not the provider's.
Options for no cookies or no tracking, and claiming everything as necessary usually don't do the trick. Plus, masked or truncated IP addresses are still (pseudonymized) data.
= You may get that nice "please accept our marketing cookies" dialog instead of the video for up to 50% of your visitors.

The Ignite architecture removes those obligations by eliminating their trigger. No cookies are set at the player level, and no personal visitor data is processed.
The GDPR position does not depend on consent UX or on visitor behaviour: playback for a visitor who declines cookies is identical to playback for a visitor who accepts, because neither state exists for Ignite. You can just show that video.
Let's walk through the architecture, your questions and confirm any configuration relevant to the specific deployment. Go see the Security & Compliance hub for the underlying documentation. Or just go for a free trial, because beyond that legal talk, we're still fun to use.