The Bunny Fonts declaration of use as GDPR / DSGVO compliant is correct. It is correct that the data transmission (such as the IP address) was warned as insecure. However, to third countries such as the USA, where the Google servers are located. Since Bunnyfonts is based in Slovakia (Europe) it is used in accordance with GDPR.
On Bunny.net:
Retake control of your user’s privacy. With a Zero Logging policy and strictly European-based systems, Bunny Fonts keeps your user’s PII data their own and helps you simplify development and achieve GDPR compliance.
German Lawsite (german language):
Andererseits werden Informationen, darunter auch die personenbezogene IP-Adresse, zumindest auch an Google-Server in den USA übertragen. Drittstaatentransfers sind aber datenschutzrechtlich nur nach den strengen Voraussetzungen der Art. 44 ff. DSGVO zul?ssig und aktuell für das Zielland USA allgemein nicht rechtskonform m?glich, weil es wegen weiter Datenzugriffsbefugnisse der US-Geheimdienste an einem hinreichenden Schutzniveau für personenbezogene Daten fehlt.
German Lawsite (english language):
On the other hand, information, including the personal IP address, is at least also transmitted to Google servers in the USA. Third-country transfers are, however, only subject to the strict requirements of Art. 44 et seq.
DSGVO permissible and currently not legally possible for the target country USA, because there is a lack of a sufficient level of protection for personal data due to the US secret services’ broad data access rights.
Source:
https://www.it-recht-kanzlei.de/google-fonts-forderung-schadensersatz-privatperson.html