An EU entity, EU hardware,
no foreign jurisdiction in the chain.
Dedicated LLM hosting in EU-Central for public sector bodies and agencies that need to keep AI workloads under EU control, with the paperwork procurement asks for.
Not a legal opinion. This page describes GPUwerk's infrastructure, corporate structure, and contractual commitments. Whether it satisfies a specific procurement requirement or security classification is for your own legal or procurement team to determine.
The sovereignty question, answered plainly
Procurement reviewers usually ask the same three questions. Here is what applies.
"Who can be compelled to hand over our data?"
The hardware is physically in EU-Central and operated by PRINT IT! SE, a Societas Europaea registered in Prague. There is no US parent, no US region, and no US-incorporated entity in the chain for a CLOUD Act order to be served on. Data residency isn't a settings toggle here, it's where the machine bolts to the rack.
"Does the provider see what we run?"
GPUwerk runs infrastructure, not models. Workloads run on a dedicated machine assigned to your organisation, behind SSH keys only you hold. Under the data processing agreement, GPUwerk does not access your content except at your request for support or where a legal obligation requires it.
"Can our legal team review the paperwork?"
Yes. A standard GDPR Article 28 DPA is published at /legal/dpa and the corporate entity details, including the competent supervisory authority, are at /legal/imprint. No certifications such as C5 or BSI Grundschutz are claimed; if your process requires one, confirm directly with us rather than assuming.
For the procurement file
The facts a reviewer will want to check against their own requirements.
| Question | Answer |
|---|---|
| Operating entity | PRINT IT! SE, Societas Europaea, Altajská 1568/2, Vršovice, 100 00 Praha 10, Czech Republic |
| Where is data physically processed? | EU-Central, on a dedicated single-tenant machine assigned to you |
| US CLOUD Act exposure? | None. No US parent, no US region, no US-incorporated entity in the chain. |
| Who can access instance content? | Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps infrastructure administrator access to the machine, as on any hosted service, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it. |
| Sub-processors for the workload? | None, listed at /legal/sub-processors |
| DPA (GDPR Art. 28)? | Published at /legal/dpa, no charge |
| Security certifications held? | None claimed, including C5 and BSI Grundschutz. Verify directly if your process requires a specific certification. |
| Supervisory authority | Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Prague, per /legal/imprint |
Questions we get from public sector buyers
Is GPUwerk exposed to the US CLOUD Act?
No. The operating entity, PRINT IT! SE, is a Societas Europaea registered in Prague, Czech Republic, with no US parent, no US region, and no US-incorporated entity in the chain for a CLOUD Act order to be served on. The hardware itself is physically located in EU-Central.
Does GPUwerk hold a government security certification such as C5 or BSI Grundschutz?
No, and we don't claim one. If your procurement requires a specific certification, confirm directly with us before assuming it applies; none is stated on this site.
Is a DPA available for procurement review?
Yes, a standard GDPR Article 28 DPA is published at /legal/dpa at no charge, and there are no sub-processors for instance workloads, listed at /legal/sub-processors.
Who operates the infrastructure?
PRINT IT! SE, a Societas Europaea registered in Prague, Czech Republic. Full corporate details, including the supervisory authority for data protection, are published at /legal/imprint.
Related pages
Send us your requirements list.
We'll tell you plainly what's covered and what isn't, before you write it into a tender.
Talk to us Deploy an instance