Trust & Security
Built for confidential
patent work.
Wunder IP runs on 100% European infrastructure. Below you'll find every guarantee, control, sub-processor and compliance reference patent attorneys ask for during procurement.
What sets us apart
GDPR-compliant is not automatically data-sovereign.
Many vendors advertise „GDPR compliant" while running on US hyperscalers under the hood. That gives US authorities CLOUD Act access, even to client data stored in Europe. The CJEU made this explicit in „Schrems II" (C-311/18). We chose to solve the problem at its root.
Common in the AI market
- EU hosting on AWS, Azure or GCP
- Standard Contractual Clauses against the CLOUD Act
- Reliance on the EU-US Data Privacy Framework
At Wunder
- Hosting with European providers (Hostinger, Hetzner, Scaleway)
- Language models on European infrastructure (Mistral, DeepSeek, GLM, Qwen, Llama, GPT-OSS)
- Confidential client data stays in the EU; US providers optional, for non-sensitive tasks only
Schrems II, CLOUD Act, Schrems III, and how we solve it.
Our commitment
Your intellectual property deserves the highest protection.
Fully GDPR-compliant and built to meet § 203 StGB professional-secrecy requirements, for patent attorneys handling sensitive client data every day.
Your data, prompts, and AI outputs are:
Compliance
GDPR
EU Data Protection Regulation
27001
ISO 27001:2022
Certified infrastructure providers
§ 203 StGB
Designed for professional secrecy
Controls
Security Controls
All controls activeUpdated 07/2026
Infrastructure security
Data protection
Access control
Compliance
Data path
Subprocessors
The following providers process data on our behalf. By default, all confidential matters stay on European infrastructure. Transactional emails are delivered via a US provider; optional frontier models are used through OpenRouter only when the user explicitly opts in for non-sensitive matters, protected by EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
Primary infrastructure (European, default)
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Hostinger | European VPS hosting | Germany (EU) | EU jurisdiction · GDPR |
| Hetzner | App hosting, databases & document processing | Germany & Finland (EU) | EU jurisdiction · GDPR |
| Scaleway | AI inference & embeddings | France (EU) | EU jurisdiction · GDPR |
| tensorx.ai | EU LLM routing (when enabled) | Ireland (EU) | EU jurisdiction · GDPR |
US subprocessors (email & optional frontier models)
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Resend | Transactional email delivery | USA | EU SCCs · EU-US Data Privacy Framework |
| OpenRouter | Optional frontier models (OpenAI, Anthropic, Google) – opt-in, non-sensitive matters only | USA | EU SCCs · EU-US Data Privacy Framework |
Documents & evidence
Resources
Policies
Documents
Data Processing Agreement (DPA / AVV)
Bilingual contract (DE/EN) per Art. 28 GDPR, including TOMs and approved sub-processors
request a copyQuestions from procurement?
We have the answers.
Security questionnaire, DPA, or a deep-dive on data sovereignty — reach out and we'll respond quickly and concretely.