Data Processing Agreement
This document is incorporated into our Terms of Service for business customers who process personal data on their instance. It has not yet been reviewed by external counsel. The version at this address is the one that applies, and it supersedes any earlier draft sent by email.
1. Parties and roles
This agreement is between PRINT IT! SE, Altajská 1568/2, Vršovice, 100 00 Praha 10, Czech Republic ("GPUwerk", "processor") and the customer named on the account ("controller"). It applies wherever the controller processes personal data on a GPUwerk instance. Where no such data is processed, this agreement has nothing to act on and imposes no obligation on either side.
2. Subject matter and duration
GPUwerk provides dedicated, single-tenant GPU compute, in one of the tiers listed on the pricing page (currently NVIDIA DGX Spark, with further tiers listed as they become available). The controller decides what runs on the instance, including whether it processes personal data at all. GPUwerk hosts the machine but does not access, read, copy, index, or analyse the content of the controller's instance. Processing under this agreement lasts for as long as the controller's account exists and continues only for the time needed to give effect to termination as described in clause 8.
3. Nature and purpose of processing
The nature of the processing is infrastructure hosting: storage on the instance's local NVMe while it runs or is stopped, and one backup copy of the workspace on GPUwerk's own backup server in the Czech Republic, refreshed about every six hours. If the account's credit reaches zero or its monthly budget is reached, the instance is released from its node and the workspace is kept only as that backup copy, for 7 days so the controller can restore it, and then deleted. If that copy cannot be made, the instance is held on its node for 24 hours and then terminated with no copy retained. The purpose is solely to make the controller's dedicated compute available, to preserve its state between stop and restart, and to recover it from a hardware failure. GPUwerk does not process the content for any purpose of its own, including training, analytics, or marketing.
4. Categories of data subjects and personal data
The controller determines what it puts on the instance, so the categories of data subjects and personal data are whatever the controller chooses to process there, for example its own customers, employees, or end users, and whatever data types its workload handles. GPUwerk has no visibility into these categories and cannot enumerate them; the controller is best placed to record them in its own Article 30 records.
5. Documented instructions
GPUwerk processes personal data on the instance only by hosting the hardware it runs on, and only for as long as the account exists. GPUwerk does not otherwise access or act on the content, so there are no further instructions to give or receive at that layer, and none are needed. If a documented instruction requires clarification, or GPUwerk considers an instruction would infringe the GDPR or another EU data protection provision, GPUwerk will inform the controller before carrying it out.
6. Confidentiality
GPUwerk ensures that persons authorised to access the platform's infrastructure have committed themselves to confidentiality, and access is limited to what their role requires, consistent with the access control measures described in our Privacy Policy, section 12.
7. Security of processing
GPUwerk applies the technical and organisational measures required by Article 32 GDPR, described in full in our Privacy Policy, section 12: a machine dedicated to a single customer, with no workload sharing between customers, SSH public key authentication with passwords disabled fleet-wide, deletion of a tenant's container and workspace before a node is offered to anyone else, and access control limiting staff access to what their role requires. That section is incorporated into this agreement by reference.
8. Deletion on termination
On termination of an instance, GPUwerk deletes the container and its workspace volume from the node, and the workspace's backup copy from GPUwerk's backup server, as described in our Terms of Service, section 7. Before a node is allocated to another customer it is sanitised: every tenant container and volume is removed from it, and the node fails its readiness check and is not allocated while any remain. This is deletion at the filesystem level. GPUwerk does not currently operate self-encrypting drives or full-disk encryption on the nodes, and does not claim a cryptographic erase. The controller is responsible for exporting anything it needs before termination, since termination is not reversible. Exhaustion of credit or the monthly budget releases the instance as described in clause 3, and termination and deletion follow 7 days later.
GPUwerk keeps one backup copy of each workspace, on its own hardware in the Czech Republic, for the purpose set out in clause 3. No other party stores or accesses it. The copy, with any personal data it contains, is deleted when the instance is terminated or the account is closed, and 7 days after a release for exhaustion of credit or the monthly budget.
9. Sub-processors
GPUwerk engages no sub-processors for the processing described in this agreement: instance workloads run on GPUwerk's own hardware in EU-Central, and no other party is in that path. The general sub-processor list for the website, billing and account side of the service, which does not touch instance content, is published at /legal/sub-processors. If GPUwerk ever engages a sub-processor for instance-level processing, it will give the controller at least 30 days' notice by email before the change takes effect, and the controller may object on reasonable grounds relating to the protection of personal data within that period.
10. Assistance with data subject requests and Article 33
Because GPUwerk cannot see the content of the controller's instance, it cannot itself locate or respond to a data subject request about that content. Where a data subject contacts GPUwerk directly about data on a customer's instance, GPUwerk will refer the request to the controller, since the controller alone can act on it. GPUwerk will otherwise give the controller reasonable assistance in responding to data subject requests, to the extent the request concerns the infrastructure layer GPUwerk operates. If GPUwerk becomes aware of a personal data breach affecting the controller's instance, it will notify the controller without undue delay, consistent with Article 33(2) GDPR, so the controller can meet its own 72-hour notification duty to its supervisory authority.
11. Audits
GPUwerk will make available the information reasonably necessary to demonstrate compliance with this agreement and will answer written questionnaires from the controller or its data protection officer. Given the nature of dedicated single-tenant hardware, this typically takes the form of documentation rather than a physical audit; where a physical audit is genuinely necessary, GPUwerk will discuss reasonable arrangements, timing and cost with the controller in good faith.
12. Governing law
This agreement is governed by the laws of the Czech Republic, on the same terms as clause 16 of our Terms of Service, which that clause sets out in full and which apply here without repetition.
13. Related documents
See also our Privacy Policy, Terms of Service, and Sub-processors.