Infrastructure your own engineers can actually check.
Dedicated single-tenant infrastructure in EU-Central, operated by an EU entity with no US parent in the chain, and the paperwork your data protection officer will ask for before a pilot goes anywhere near production data.
Not legal advice. This page describes GPUwerk's infrastructure, corporate structure, and contractual commitments. Whether it satisfies your specific obligations under Estonian or EU data protection law is a question for your own data protection officer or legal counsel, not for this website.
Why we expect a technical audience here
Estonian buyers tend to skip the sales pitch and go straight to the SSH prompt. e-Residency, i-Voting, and a public sector that's run mostly digital since the early 2000s have made "show me the machine, not the marketing" a fairly normal opening request, and Estonian IT teams are used to evaluating infrastructure vendors on specifics rather than logos. So here's the specific part: a single DGX Spark is a dedicated machine, not a virtualised slice, and root access is yours through SSH keys, with password login disabled fleet-wide. If your team wants to inspect the box before committing budget to a pilot, that's a request we're used to.
Where does the data sit?
On a dedicated machine in EU-Central, in the Czech Republic. It's not a region toggle in a US console; it's a specific rack, and the operating company is a Societas Europaea registered in Prague with no US parent.
Who is the vendor, legally?
PRINT IT! SE. Company details, including the address and the competent supervisory authority for GPUwerk's own processing, are published at /legal/imprint. This is a Czech entity, so GPUwerk itself answers to the Czech supervisory authority, not Estonia's Andmekaitse Inspektsioon, the same way any other EU-Central vendor you'd work with wouldn't either.
Can procurement get the paperwork?
Yes. A standard Art. 28 GDPR data processing agreement is at /legal/dpa, and there are no sub-processors on instance workloads, listed at /legal/sub-processors. No certifications such as ISO 27001 are claimed; if one is a hard requirement for you, ask before assuming it applies.
The general landscape, stated plainly
Estonia's data protection authority is the Andmekaitse Inspektsioon, and it oversees your own company's processing regardless of which EU country hosts your infrastructure. GPUwerk, as a Czech-registered operator, answers to the Czech supervisory authority for its own processing, not to the AKI. Those are two separate relationships, and this page can't collapse them into one. What GPUwerk can state factually: the infrastructure runs in EU-Central under an EU entity, GDPR and the EU AI Act apply to processing done there the same way they apply anywhere in the Union, and a standard Art. 28 DPA is available so your own DPO can run their normal review. The specifics of how Estonia's implementing rules interact with your particular use case, including anything touching public sector or health data, are for your own counsel to work through, not a hosting vendor's marketing page.
For the compliance file
The facts to check against your own checklist.
| Question | Answer |
|---|---|
| Operating entity | PRINT IT! SE, Societas Europaea, Altajská 1568/2, Vršovice, 100 00 Praha 10, Czech Republic |
| Where is data physically processed? | EU-Central, on a dedicated single-tenant machine assigned to you |
| US CLOUD Act exposure? | None. No US parent, no US region, no US-incorporated entity in the chain. |
| Pricing | $0.79/hour for a single DGX Spark, $1.79/hour for a two-node cluster (128GB unified memory each) |
| Who can access instance content? | Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps standard infrastructure administrator access, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it. |
| Sub-processors for the workload? | None, listed at /legal/sub-processors |
| DPA (Art. 28 GDPR)? | Published at /legal/dpa, no charge |
| Certifications held | None claimed, including ISO 27001. Confirm directly if your process requires one. |
Questions we get from Estonian buyers
Where is the hardware located?
EU-Central, in the Czech Republic, inside the EU with no cross-border transfer question to resolve. Network latency to Tallinn is typical for any EU-Central provider serving the Baltics.
Which authority is responsible for data protection oversight?
GPUwerk is operated by PRINT IT! SE, registered in Prague, so the competent Czech supervisory authority applies to GPUwerk directly. Your own company's processing is separately overseen by Estonia's Andmekaitse Inspektsioon (Data Protection Inspectorate). That's a question for your own data protection officer, not something GPUwerk can answer on your behalf.
Is a DPA available under Art. 28 GDPR?
Yes, published at /legal/dpa at no charge. There are no sub-processors for instance workloads, listed at /legal/sub-processors.
Is this legal advice?
No. This page describes GPUwerk's infrastructure and corporate structure. Whether it satisfies your specific compliance obligations is a question for your own data protection officer or legal counsel.
Related pages
Send your DPO's questions our way.
We'll tell you plainly what's covered and what isn't, before it goes into a contract.
Talk to us Deploy an instance