Security · Data protection · Compliance

Compliance is not an extra for us: it is our business model

Secure. Compliant. Verifiable. AI with responsibility. We develop personalized video solutions so that data protection, IT security, accessibility, documentation and responsible AI use are considered from the start, as the foundation for approvable projects.

  • DSGVO / BDSG
  • TDDDG / Consent
  • BFSG / WCAG 2.1
  • EU AI Act
  • ISO 27001 data centers

Our principle: personal data is processed exclusively by our own rule-based render engine in German data centers, never by AI models. AI creates creative building blocks; humans review and approve.

Why clients trust us

Many show nice results. Few deliver DPA, deletion concept and accessibility at the same time.

That is exactly where we start, so that your teams in marketing, data protection, IT, procurement, compliance and legal move faster.

German company

Owner-managed, directly reachable, short paths: without anonymous offshore structures.

EU/DE-oriented processing

Hosting in Germany, clear responsibilities, traceable sub-processor chains, clean documentation.

Compliance-ready instead of “later, somehow”

DPA, TOMs, deletion concept, roles, approvals and audit evidence are planned from the start.

Responsible AI

Transparency, human control, clear limits of use, and never personal data inside an AI model.

Data protection, IT security, AI

What we concretely do

Data protection that is not just claimed

  • only the data really needed for personalization
  • DPA, TOMs, role and rights concept
  • documentable deletion and approval processes
  • TLS 1.3, encryption at rest, 2FA, VPN

IT security & hosting in Germany

  • hosting in Germany (Hetzner, ISO 27001)
  • carbon-neutral data center, 100% green power
  • own systems on dedicated hardware, no multi-tenant instances
  • firewalls, DDoS protection, backups, disaster recovery plan

AI that builds trust instead of questions

  • no personal data in AI models: the separation is documented
  • clear labeling and transparency where sensible or required
  • human quality control before publication
  • no “AI at any cost”, but AI with responsibility

What we consider in detail

So your project is approved right away

Our standard is not just “works” but “works in the reality of large organizations”, with internal approvals, governance, review questions and documented decisions.

Data protection & law

  • GDPR- and BDSG-oriented project structure
  • data processing agreement incl. TOMs
  • data minimization and defined purposes
  • clean deletion periods and evidence
  • transparent sub-processor list

Tracking & consent

  • clean separation of necessary and optional technologies
  • cookie/tracking setups with TDDDG in mind
  • consent-dependent integration of external services
  • analytics setups as data-sparing as possible
  • fewer unnecessary third-party dependencies

Digital responsibility

  • BFSG-sensitive design of digital services
  • captions, text alternatives, clear contrasts
  • resource-saving delivery and optimized data volumes
  • carbon-neutral hosting in Germany
  • support for ESG and sustainability goals

AI governance

  • clear rules for AI-generated content
  • transparency about AI use and origin
  • human review and approval steps
  • protection against misleading or inappropriate outputs
  • brand-safe guardrails for tone and visuals

EU-oriented governance

Why it often gets unnecessarily complicated with non-EU providers

Good creative work can be bought almost anywhere. Clean legal, technical and organizational embedding in European requirements cannot.

Review areaWith WonderlandmoviesTypical friction with non-EU / unclear setups
Data flowsClearly describable, EU/DE-based, cleanly documentableadditional reviews on third countries, sub-processors and legal bases
DPA & evidencealigned with compliance departmentsunclear responsibilities, incomplete documents, slow coordination
Personal data & AIstrictly separated: data only in our own render engineblack-box use of AI services with customer data
Accessibilityconsidered early in concept, player and deliveryoften considered late or not at all
AI transparencywith clear guardrails and review processesno reliable chain of responsibility
Internal approvalsmore straightforward because we anticipate expert questionslong loops between marketing, legal, DPO and IT

We do not claim that only a German or EU-oriented setup is possible. But we know from practice: for many companies it becomes significantly easier, faster and more robust.

Project process

How a project with us works

  1. 1

    Short briefing & risk review

    Define goal, audience, data sources and personalization. Check which data protection, tracking, AI or accessibility questions are relevant, and what needs documenting and approving.

  2. 2

    Concept & implementation

    Structure template, data logic, delivery and hosting cleanly. Plan accessible use and brand-safe approvals. AI only where it is sensible, justifiable and controllable.

  3. 3

    Launch & evidence

    Productive delivery with clear responsibilities. Documentation for data protection, IT or procurement, on request with deletion logic, checklists and internal review support.

FAQ

Questions from data protection and IT reviews

Is the solution GDPR-compliant?

Yes. Processing exclusively in German data centers, data processing agreement (DPA) including TOMs, no third-country transfer without a legal basis.

Is personal data processed by AI?

No. Personal data is processed exclusively by our own rule-based render engine. AI services generate creative building blocks in advance (voices, visuals, text variants), without reference to individual persons.

Do you offer a data processing agreement?

Yes. We provide a DPA including TOMs, sub-processor list and data protection concept, adaptable to your compliance department.

Which data is required?

Only the variables to be personalized (e.g. first name, product, location). Processing is purpose-bound, logged and documented, with clear deletion periods.

How is personal data protected?

Transport encryption (TLS 1.3), encryption at rest, access restrictions, role-based permissions, logging and automatic deletion as agreed.

How long are data and videos stored?

As agreed: immediate deletion after delivery or automatic periods (e.g. 30 or 90 days). Deletion logs and evidence are available on request.

How do you protect brand content from misuse?

Template approvals, rights and role model, watermarks, expiring links, rate limits and abuse detection.

Where is data processed?

In certified German data centers of Hetzner Online GmbH (ISO 27001, Nuremberg/Falkenstein). No cloud systems outside the EU.

Do you use your own systems or third parties?

We operate all systems ourselves on dedicated hardware. No multi-tenant instances, every customer gets their own environment. Active measures: firewalls, DDoS protection, two-factor authentication, VPN access, backup strategy, disaster recovery plan.

Are the videos accessible under the German Accessibility Act (BFSG)?

Yes. Our videos can be delivered fully accessible, including closed captions, audio description and an accessible player with keyboard and screen-reader support (WCAG 2.1, BFSG). The obligation has applied since 28 June 2025, we already meet it in full.

How sustainable is the operation?

Our servers run on 100% green electricity in a carbon-neutral data center. We rely on paperless processes, energy-efficient workflows, resource-saving delivery and automatic data deletion.

Is there an ESG strategy?

Yes. Wonderlandmovies meets ESG criteria in the areas of environment (E), security & compliance (S) and governance (G).

You do not just want personalized videos. You want a solution that holds up internally.

Start live demo Book a strategy call

On request we deliver the right documents for data protection, IT, compliance or procurement reviews, so a good idea becomes an approved project.