Patient data has a higher bar.
Host where you control it.
Private LLM hosting on a dedicated machine in EU-Central, for clinics, hospital groups, and health tech teams handling special-category data under GDPR Article 9.
Not medical, legal, or compliance advice. This page describes GPUwerk's infrastructure and contractual commitments. Whether a given use of patient data has a valid legal basis under Article 9, and what else your organisation must do to process it lawfully, is for your own data protection officer or counsel to assess.
Why health data needs more than the general answer
Patient records, diagnoses, and clinical notes are special-category data under GDPR Article 9: the bar for lawful processing is higher than for ordinary business data, and the consequences of getting it wrong are worse.
"Our data leaves the EU"
It doesn't. The hardware is physically in EU-Central and operated by PRINT IT! SE, a Societas Europaea registered in Prague. There is no US parent, no US region, and no US-incorporated entity in the chain. For patient data this matters more than for most workloads, since it removes one of the harder international-transfer questions from the assessment.
"The provider trains on our data"
GPUwerk runs infrastructure, not models: patient data processed on your dedicated machine is handled by software you installed, behind SSH keys only you hold. Under the data processing agreement, GPUwerk does not access your workspace's content except at your request for support or where a legal obligation requires it, so there is nothing for us to train on.
"Clinicians use consumer AI tools informally"
Staff drafting notes or summarizing records in a public AI tool is a real exposure, not a hypothetical one. A sanctioned alternative on your own instance, same chat interface, keeps that workflow off third-party infrastructure. See the private ChatGPT setup →
Where this stands next to HIPAA
If your organisation also has US obligations, keep the two frameworks separate.
| Question | Answer |
|---|---|
| Is GPUwerk HIPAA compliant? | No. HIPAA is a US federal framework. GPUwerk is a Czech entity operating in EU-Central, outside HIPAA's jurisdiction, and we do not offer a HIPAA business associate agreement. |
| Is GPUwerk GDPR-relevant? | Yes, in the sense of providing an EU-Central processing location and an Article 28 DPA. Whether your specific processing satisfies GDPR, including Article 9's basis for special-category data, is your assessment as controller. |
| Where is data physically processed? | EU-Central, on a dedicated single-tenant machine assigned to you |
| Who can access instance content? | Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps infrastructure administrator access to the machine, as on any hosted service, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it. |
| Sub-processors for the workload? | None, listed at /legal/sub-processors |
| DPA (GDPR Art. 28)? | Published at /legal/dpa, no charge |
| Certifications held? | None claimed on this page or elsewhere on the site. If your procurement requires a specific certification such as ISO 27001, verify directly with us before relying on this page. |
Questions we get from health teams
Does this meet GDPR Article 9 requirements for health data?
GPUwerk provides the infrastructure evidence relevant to that assessment: EU-Central hardware and operations, a dedicated single-tenant machine, an Article 28 DPA, and no sub-processors for instance content. Article 9 also requires a specific legal basis for processing special-category data, which is a decision for your organisation as controller, not something GPUwerk's infrastructure can supply on its own.
Is GPUwerk HIPAA compliant?
No, and we don't claim it. HIPAA is a US federal framework; GPUwerk is a Czech Societas Europaea operating entirely in EU-Central, outside HIPAA's jurisdiction and without a HIPAA business associate agreement. If your organisation has US HIPAA obligations, this is not the right infrastructure basis for those specific workloads; talk to your compliance team about what applies.
Do you sign a DPA for patient data?
Yes, a standard GDPR Article 28 DPA is published at /legal/dpa at no charge, and there are no sub-processors for instance workloads.
Can we run this past our DPO before deciding?
Yes, and you should. We answer DPO questionnaires and provide documentation of the physical location, access controls, and deletion procedures directly. Email hello@gpuwerk.com.
Related pages
Bring your clinical AI workload to a machine you control.
Talk to the people who run the racks, or start with a pilot and a practical rollout plan.
Talk to us Deploy an instance