Legal

Privacy Policy

Information under Articles 13 and 14 GDPR · Last updated August 26, 2026

Draft for review. This document is a working draft prepared for internal review. It has not yet been reviewed by qualified legal counsel and must be before anyone relies on it.

1. Who is responsible

The controller for the processing described here is:

PRINT IT! SE
Altajská 1568/2, Vršovice
100 00 Praha 10
Czech Republic
Register court: Municipal Court in Prague (Městský soud v Praze) · Registration number: Section H, Insert 2104, Company ID (IČO) 069 60 090
Email: privacy@gpuwerk.com

Data Protection Officer: [NAME AND CONTACT OF DPO, IF ONE IS APPOINTED]. Until a DPO is named, privacy enquiries reach us at privacy@gpuwerk.com.

2. The most important point: we do not look inside your instance

GPUwerk rents whole dedicated NVIDIA DGX Spark machines. An instance is single-tenant bare metal: you are the only tenant on that physical machine for the duration of your rental. Access is by SSH public key only; password authentication is disabled across the fleet.

We do not access, read, copy, index, analyse, or otherwise process the content of your workloads: your data, your models, your prompts, your outputs, your logs inside the machine. We are an infrastructure provider. What runs on the machine is yours.

If you process personal data on your instance, you are the controller for that data and GPUwerk acts as a processor. A data processing agreement under Article 28 GDPR is available on request from privacy@gpuwerk.com. We engage no sub-processors for customer workloads: the hardware is ours, it sits in EU-Central, and nobody else is in that path.

The rest of this policy therefore describes only the personal data we process as a controller in our own right: the data needed to run an account, bill it, support it, and operate the website.

3. What we process, why, and on what legal basis

CategoryPurpose and legal basis
Account data: name, business name, email address, console login identifiers, role and permissions Creating and administering your account, authenticating you, communicating about the service. Article 6(1)(b) GDPR, performance of a contract.
Billing data: billing address, VAT identification number, credit top-ups, per-minute usage records, invoices, payment references Charging for use, issuing invoices, meeting tax and commercial retention duties. Article 6(1)(b) and Article 6(1)(c) GDPR.
Authentication data: SSH public keys you upload, API tokens, session records Granting you access to your instances and to the console. SSH public keys are provisioned onto the instance; we hold no private keys. Article 6(1)(b) GDPR.
Technical and operational logs: IP address, timestamps, console and API requests, instance start, stop and termination events, hardware health telemetry Operating the platform, billing accuracy, troubleshooting, detecting abuse and attacks, security. Article 6(1)(b) and Article 6(1)(f) GDPR, our legitimate interest in a secure and correctly billed service. This telemetry describes the machine, not the workload running on it.
Support correspondence: emails, tickets, and whatever you choose to include in them Answering your enquiry and keeping a record of it. Article 6(1)(b) GDPR, or Article 6(1)(f) where you are not yet a customer.
Website usage data: pages requested, referrer, approximate region, browser and device type Delivering the site and understanding in aggregate which pages are useful. Article 6(1)(f) GDPR for strictly necessary processing; Article 6(1)(a) GDPR, your consent, for anything requiring cookies or similar storage that is not strictly necessary.

Where a legal basis is consent, you can withdraw it at any time with effect for the future. Withdrawal does not affect processing carried out before it.

4. Where the data comes from

Almost all of it comes from you directly: what you enter in the console, what you write to support, what your browser sends when it requests a page. If you are named as a contact person by a company that holds the contract, we receive your business contact details from that company. We do not buy personal data and we do not enrich it from third-party sources.

5. Who receives data

Inside our organisation, only staff who need it: operations, billing, and support. Beyond that, personal data on the website and billing side may be handled by service providers acting as processors under Article 28 GDPR:

The bracketed entries above are placeholders. They must be replaced with the actual vendors, or removed, before this policy is published. We also disclose data where a law or a binding order from a competent authority requires it.

None of these providers touches customer workloads. They exist on the website and billing side only.

6. No transfers outside the EU and EEA

Our hardware is in EU-Central. Customer instances, and the personal data described above, are processed within the European Union and the European Economic Area. We do not transfer this data to third countries. If that ever changes, we will update this policy first and put a valid Chapter V GDPR transfer mechanism in place before any transfer happens.

7. Instance data lifecycle

Your instance's /workspace lives on the node's local NVMe while the instance runs. Stopping the instance copies that workspace to storage we operate in EU-Central, deletes the container and its workspace volume from the node, and returns the node to the pool; starting the instance again restores the workspace onto whichever node is free at the time.

When you terminate an instance, we delete the container and its workspace volume from the node and delete the stored copy of the workspace. Before a node is allocated to another customer it is sanitised: every tenant container and volume is removed from it, and the node fails its readiness check and is not allocated while any remain. This is deletion at the filesystem level. We do not currently operate self-encrypting drives or full-disk encryption on the nodes, and we therefore do not claim a cryptographic erase.

You are responsible for your own backups. Termination is not reversible and we cannot recover a terminated instance for you, because the stored copy is deleted along with it.

8. Cookies and local storage

The console uses strictly necessary cookies and browser local storage to keep you signed in and to remember basic interface preferences. These are required for the service to work and are set on the basis of Article 6(1)(f) GDPR and the corresponding national implementation of the ePrivacy Directive.

Any cookie or similar technology that is not strictly necessary, including analytics or marketing storage, is set only after you consent, and you can change or withdraw that choice at any time. [CONFIRM WHETHER NON-ESSENTIAL COOKIES OR ANALYTICS ARE ACTUALLY IN USE, AND NAME THEM HERE OR DELETE THIS PARAGRAPH.]

9. How long we keep things

DataRetention
Account dataFor the life of the account. On closure we anonymise it rather than delete it, because the billing records it is attached to have a statutory retention period. See section 10a.
Invoices and accounting recordsFor the statutory retention period applicable to us, currently 10 years, per Czech accounting and VAT record-keeping obligations.
SSH public keys and API tokensUntil you remove them, or until the account is closed.
Technical and operational logs[LOG RETENTION PERIOD, e.g. 30 OR 90 DAYS], then deleted, unless a specific security incident requires us to keep a record longer.
Support correspondence[SUPPORT RETENTION PERIOD] after the matter is closed.
Instance contentsDeleted from the node and from our archive storage on termination. A stopped instance's workspace is kept in that storage until you terminate.

10. Your rights

Under the GDPR you have the right to:

Write to privacy@gpuwerk.com and we will respond within the periods the GDPR sets. If your request concerns personal data that a customer processes on their own instance, we will refer you to that customer, since they are the controller for it and we cannot see that data.

You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. The authority competent for us is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic.

10a. Closing your account, and what closure actually does

You can close your account yourself, from the console or with POST /v1/account/closure. Closure is not immediate: it takes effect fourteen days after you ask for it, and you can cancel it at any point during those fourteen days. We email you when a closure is scheduled, so that a closure requested by someone who is not you can be stopped before anything happens. Terminate or stop your instances first; we will not close an account that still has a machine running.

When the fourteen days elapse we remove your name, your email address, your profile picture, the link to whichever provider you sign in through, and every SSH key and API key on the account. After that nobody can sign in to it and it holds nothing that identifies you.

We do not delete the account record itself, and you should know why. Your invoices, payments and ledger entries are attached to it, and Czech accounting and tax law requires us to keep those records for years after the account is gone. Deleting the record would either destroy documents we are legally required to retain or leave them attached to nothing. So the record survives as a numbered stub with no personal data in it. Article 17(3)(b) GDPR permits exactly this, and Article 17(3)(e) applies to the accounting records themselves. Once the retention period expires those records are deleted too.

What we cannot undo: closure is final at the end of the fourteen days, and your instance workspaces are deleted with it. Export anything you want to keep first.

10b. Taking your data with you

You can download everything we hold about your account at any time, as a single JSON file, from the console or with GET /v1/account/export. It contains your account details, your full billing ledger and payment history, your instances and their event log, your SSH keys, and the list of messages we have sent you. It does not contain API key or token values, because we store only their hashes and could not include them if we wanted to. Instance workspaces are separate and larger: a stopped instance's workspace is available from GET /v1/instances/{id}/workspace.

This is your Article 20 GDPR portability right and, for business customers, the switching and retrieval rights under the EU Data Act. There is no charge for it, and no charge for the bandwidth to move your data to another provider.

11. Is providing data mandatory

There is no statutory obligation to give us your data, but account and billing data are necessary to enter into and perform the contract. Without them we cannot open an account or provide instances. Everything else is optional.

12. Security

We apply technical and organisational measures appropriate to the risk, in line with Article 32 GDPR. On the platform side this includes single-tenant bare metal with no workload sharing between customers, SSH public key authentication with passwords disabled fleet-wide, deletion of a tenant's container and workspace before the node is offered to anyone else, and access control limiting staff access to what their role requires.

13. Changes to this policy

We update this policy when the service or the law changes. The current version always lives at this address with the date of the last update at the top. If a change materially affects how we process your personal data, we will tell account holders by email before it takes effect, or otherwise give reasonable advance notice in the console.

14. Related documents

See also our Imprint and our Terms of Service. The Article 28 data processing agreement is available on request.