Member health data is more sensitive than a booking app.
Host where you control it.

Private LLM hosting on a dedicated machine in EU-Central, for gyms, studios, and wellness chains handling intake forms, injury history, and program notes tied to individual members.

Not medical or legal advice. This page describes GPUwerk's infrastructure and contractual commitments. Whether a member intake form, injury note, or wellness questionnaire counts as special-category data, and what basis you need to process it lawfully, is for your own data protection officer or counsel to assess.

Why member data needs more than the general answer

A gym or wellness chain's records go beyond membership billing: PAR-Q intake forms, injury history, trainer notes on physical limitations, sometimes body composition data. Much of this sits close to health data even where the business itself isn't a healthcare provider.

"It's just a fitness assessment"

A trainer summarizing intake forms or drafting personalized program notes with a public AI tool sends member injury and health-adjacent detail to a third party your membership agreement never named as a recipient.

"We only track bookings and payments"

Most chains also hold more than that: cancellation reasons, coach feedback, sometimes referral notes from a physiotherapist. A dedicated instance keeps all of it inside infrastructure you control instead of a shared cloud tenancy.

"Staff already use public AI tools to save time"

Front-desk and coaching staff drafting member communications in a public tool is a real exposure, not a hypothetical one. A sanctioned alternative on your own instance, same chat interface, keeps that workflow off third-party infrastructure. See the private ChatGPT setup →

Where this stands next to a medical or HIPAA product

If a wellness program includes clinical components, keep the two questions separate.

QuestionAnswer
Is GPUwerk a certified medical or HIPAA product?No. GPUwerk is general-purpose GPU infrastructure. It is not a certified medical device, and we make no HIPAA claim; GPUwerk is a Czech entity operating in EU-Central, outside HIPAA's jurisdiction.
Where is data physically processed?EU-Central, on a dedicated single-tenant machine assigned to you
Who can access instance content?Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps infrastructure administrator access to the machine, as on any hosted service, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it.
Sub-processors for the workload?None, listed at /legal/sub-processors
DPA (GDPR Art. 28)?Published at /legal/dpa, no charge
Certifications held?None claimed on this page or elsewhere on the site. If your franchise agreement or insurer requires a specific certification, verify directly with us before relying on this page.

Questions we get from gyms and wellness chains

Is this compliant for member health questionnaires?

GPUwerk provides the infrastructure relevant to that assessment: EU-Central hardware, a dedicated single-tenant machine, an Article 28 DPA, and no sub-processors for instance content. Whether a specific questionnaire counts as special-category data under GDPR Article 9, and what legal basis you need to process it, is a decision for your organisation as controller.

Is GPUwerk a medical or HIPAA-compliant product?

No. GPUwerk is general-purpose GPU infrastructure, not a certified medical device or health platform, and we make no HIPAA claim; GPUwerk is a Czech entity operating in EU-Central, outside HIPAA's jurisdiction. If your program includes clinical assessment, treat this as infrastructure only and get your own compliance sign-off.

Can members' PAR-Q or injury history go on this?

It can be processed on your dedicated instance, which keeps it off shared public AI infrastructure. Whether that data qualifies as special-category health data under your jurisdiction's rules, and what safeguards you need beyond hosting, is for your data protection officer or counsel to determine.

Do you sign a DPA for member data?

Yes, a standard GDPR Article 28 DPA is published at /legal/dpa at no charge, and there are no sub-processors for instance workloads.

Related pages

See how other member-facing and health-adjacent businesses use private LLM hosting: healthcare, event and conference organizers, and hospitality. Or start from the private LLM hosting overview.

Related pages

Bring your member data workload to a machine you control.

Talk to the people who run the racks, or start with a pilot and a practical rollout plan.

Talk to us Deploy an instance