OMR Reviews
find out more"I have finally found a tool that allows me to embed videos on my website in compliance with GDPR and without additional cookies."
Ignite is European-hosted, cookie-free, and GDPR-compliant. This page brings together the answers, the technical detail, and the documents a security or data-protection review looks for: from data residency and legal jurisdiction to sub-processors and the DPA.

Most video platforms add work to a data-protection review: a cookie banner to document, a transfer outside the EU to justify, a spread of sub-processors to check. Ignite removes those at the architecture level, not through settings you configure after the fact. Four points account for most of the difference.
The strongest position in a data-protection review is the data that is never collected. For video delivery, Ignite captures no IP addresses (not anonymised, not briefly stored, never collected at the infrastructure level) and sets no cookies. Several sections of a standard assessment then do not apply: no consent basis to document, no viewer-data breach scope, no profiling to explain.

All infrastructure and data sit in the EU with certified sub-processors, so there are no standard contractual clauses to negotiate and no third-country transfer to record. Ignite Video GmbH is a German company, so the contract itself is governed by European law rather than US jurisdiction.
Every layer of access control is available: password protection per video, domain restriction per embed, and CDN Security that gates every file at the infrastructure level. Storage is isolated per customer and admin access is role-based. Content stays in the context you set for it, even if an embed URL is forwarded.
The documents follow the structure of an assessment. The DPA carries the named sub-processor list and the technical measures; the security documentation answers a questionnaire point by point; the legal opinion covers the cookie-free position. Tell us what your review needs and we will answer your questions.
The headline position on each item a security questionnaire tends to cover. Full evidence sits in the DPA and the documentation we send.
How we handle this | |
|---|---|
| Hosting & data residency | EU only. No own infrastructure, certified sub-processors, no transfer to third countries, no SCCs required. |
| Data ownership | Customer owns all stored data; Ignite is processor. |
| Sub-processors | EU-Hosting. Each ISO 27001 and/or SOC 2 certified. Named in the DPA, 30 days notice before any change. < 5, not 50. |
| Viewer personal data | None processed for video delivery. No cookies, and no IP address captured (not anonymised, not briefly stored, never collected at the infrastructure level). |
| Personal data appearing within video content | Distinct from viewer data. If your videos show or reference identifiable people, you remain the controller of that content and its legal basis; Ignite processes the file as instructed, under the DPA. |
| AI features | Optional captions, translation, transcripts run on European infrastructure. Your content is not used to train models. |
| Regulatory compliance | Fully GDPR-compliant. Cookie-free architecture independently reviewed. Other frameworks addressed on request. |
| Legal jurisdiction & governing law | Ignite Video GmbH is a German company. The contract is governed by German and European law, not US jurisdiction. |
| Ownership & financial stability | Self-financed, with no venture-capital investors. No exit clock or ownership change forces a shift in pricing, terms, or a migration timeline. |
| Encryption | AES-256 at rest across storage, database, and backups. TLS 1.2+ in transit, HTTPS enforced. |
| Access & authentication | Role-based access, four levels. MFA, mandatory-capable for enterprise. SSO via Entra ID or others; Password policy enforces complexity and locks out after repeated failed attempts. |
| Monitoring & logging | Centralised logging and audit trails with tamper protection and alerting on security-relevant events. |
| Penetration testing | External penetration testing carried out by an independent security firm, alongside automated security scanning in the pipeline. Summary available as part of your documentation request. |
| Multi-brand & multi-department separation | Separate workspaces give full separation of content, roles, and settings for holding structures or multiple departments in one account. Category-level access is available as a lighter-weight option within a single workspace. |
| Data retention & deletion | Customer data deleted from primary storage within 30 days of contract end; backups within the agreed retention window. Deletion confirmation on request. |
| Still fun to use | Everything we mentioned, but it is still fun to use. Easy and fast ux within our backend app and also a great modern player for your viewers. Both things marketing and product teams love. |
The detailed documentation comes with our DPA and through our team rather than as anonymous downloads, so version control stays clean and you always have a person for follow-up questions. Tell us what your review needs.
The narrative version: data-flow diagram, consent-obligation explanation, the review scenario in your language.
Details on why we believe that cookie and consent-free is the best way to host your videos.
The product-level privacy deep-dive: what is processed, what is not, and why.