LLM hosting that survives a CNIL review.

Dedicated single-tenant infrastructure in EU-Central, operated by an EU entity with no US parent in the chain, and a data processing agreement your DPO can attach to the file before the pilot starts.

Not legal advice. This page describes GPUwerk's infrastructure, corporate structure, and contractual commitments. Whether it satisfies your specific obligations under French or EU data protection law is a question for your own DPO or legal counsel, not for this website.

What a French DPO checks before signing off

Most French procurement reviews for an AI vendor come down to the same handful of points.

Where is the data actually processed?

On a dedicated machine in EU-Central, in the Czech Republic. It's not a region selector in a US console; it's a specific rack, run by a Societas Europaea registered in Prague with no US parent.

Who is the vendor, and who regulates them?

PRINT IT! SE. Full company details, including the address and the competent supervisory authority for GPUwerk's own processing, are at /legal/imprint. It's a Czech entity, so it isn't the CNIL that oversees GPUwerk directly, in the same way it wouldn't oversee any other vendor headquartered outside France. Your own processing activities remain within the CNIL's remit as normal.

Can we get the contractual paperwork?

Yes. A standard Art. 28 GDPR DPA is at /legal/dpa, and there are no sub-processors on instance workloads, listed at /legal/sub-processors. No certifications such as SecNumCloud are claimed; if that's a hard requirement for your project, confirm directly rather than assuming it applies.

The general landscape, stated plainly

France's data protection authority is the CNIL (Commission Nationale de l'Informatique et des Libertés), and it's the reference point most French companies use when assessing a vendor. GPUwerk isn't a French entity and doesn't fall under CNIL supervision directly, but the processing GPUwerk hosts still happens inside the EU, under GDPR, the same as it would with any EU-Central provider. The EU AI Act applies to relevant use cases across the Union as well, France included. What GPUwerk can state as fact: EU-Central location, EU operating entity, no US parent, and a standard DPA available on request. Whether that combination is sufficient for a given use case under French implementing legislation (the loi Informatique et Libertés) or any sector-specific rule you're subject to is a determination for your own legal team, not something a hosting page can settle.

For the compliance file

The facts to check against your own checklist.

QuestionAnswer
Operating entityPRINT IT! SE, Societas Europaea, Altajská 1568/2, Vršovice, 100 00 Praha 10, Czech Republic
Where is data physically processed?EU-Central, on a dedicated single-tenant machine assigned to you
US CLOUD Act exposure?None. No US parent, no US region, no US-incorporated entity in the chain.
Pricing$0.79/hour for a single DGX Spark, $1.79/hour for a two-node cluster (128GB unified memory each)
Who can access instance content?Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps standard infrastructure administrator access, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it.
Sub-processors for the workload?None, listed at /legal/sub-processors
DPA (Art. 28 GDPR)?Published at /legal/dpa, no charge
Certifications heldNone claimed, including SecNumCloud. Confirm directly if your process requires one.

Questions we get from French buyers

Where is the hardware located?

EU-Central, in the Czech Republic. The operating entity, PRINT IT! SE, is a Societas Europaea registered in Prague, with no US parent, no US region, and no US-incorporated entity in the chain.

Does the CNIL oversee GPUwerk?

No. GPUwerk is operated by a Czech entity, so the competent Czech supervisory authority applies to GPUwerk's own processing, not the CNIL. Your company's own processing activities remain subject to the CNIL as France's data protection authority, the same as with any other EU-based vendor you use. Whether a specific arrangement satisfies your obligations under French law is a question for your own DPO or counsel.

Is a DPA available under Art. 28 GDPR?

Yes, published at /legal/dpa at no charge. There are no sub-processors for instance workloads, listed at /legal/sub-processors.

Is this legal advice?

No. This page describes GPUwerk's infrastructure and corporate structure. Whether it satisfies your specific obligations is a question for your own DPO or legal counsel.

Related pages

Send your DPO's checklist our way.

We'll tell you plainly what's covered and what isn't, before it goes into a contract.

Talk to us Deploy an instance