Candidate data across dozens of clients doesn't belong in someone else's model.
Keep it on your machine.

Private LLM hosting on a whole dedicated machine in EU-Central, for recruiting and staffing agencies that screen and place candidates for many client companies at once, and need to do it without routing candidate personal data through a consumer AI product.

Not legal advice. This page describes GPUwerk's infrastructure and contractual commitments. It is not an opinion on your obligations as a data controller for candidate personal data, or on any specific client agreement's confidentiality terms. Check with your own counsel before deciding what can run where.

Why agencies end up here

This page is for staffing and recruiting agencies handling candidate pipelines for many client companies at once, not for an internal HR team screening applicants for a single employer. If that's your situation instead, see our page on private AI for internal HR and recruiting.

An agency's data problem is bigger than one company's

A single-employer HR team runs AI over its own applicant pool. An agency runs it over candidate CVs, assessments, and reference notes spanning many client companies, some of whom compete with each other. Consumer AI products, whose terms may allow retention or review of what's submitted, put every one of those client relationships at risk at once, not just one. The infrastructure question is separate and answerable: does the machine belong to your agency, and who else can reach it.

"The provider trains on what we submit"

On a GPUwerk instance, the model runs on hardware assigned to your agency alone. GPUwerk operates the machine but, under the data processing agreement, does not access your content except at your request for support or where a legal obligation requires it. There is nothing for us to train on, and no other tenant shares the GPU.

"Recruiters paste CVs into ChatGPT anyway"

Blocking access pushes it to personal devices. A sanctioned alternative on your own instance, same chat interface, keeps that workflow on hardware only your agency controls. See the private ChatGPT setup →

Where agencies use it

Screening and drafting assistance, reviewed by a recruiter before anything reaches a client or a candidate.

CV screening and shortlisting

First-pass matching of candidate CVs against a role brief, on an instance where the candidate pool for every client stays on your agency's own infrastructure.

Candidate summary and reference drafting

First drafts of candidate submission summaries and reference-check write-ups, built from the candidate's file on the same instance, instead of copying personal data into a browser tab.

Client and candidate correspondence

Draft outreach and placement update emails grounded in the actual candidate and role data, for a recruiter to check before it goes out.

What's actually in the contract

For your data protection lead or IT director to review directly.

QuestionAnswer
Where does it run?EU-Central, on a dedicated single-tenant machine assigned to your agency
Who operates it?PRINT IT! SE, a Societas Europaea registered in Prague, Czech Republic. No US parent entity.
Who can reach the instance?Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps infrastructure administrator access to the underlying machine, as on any hosted service, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it.
Does GPUwerk read candidate records?No. We host the hardware and, under the DPA, do not access, read, copy, index or analyse workload content.
Separation between your own clients' candidate pools?Enforced by whatever placement software you run on the instance, not by GPUwerk; the instance itself is single-tenant to your agency only.
Sub-processors for the workload?None, listed at /legal/sub-processors
DPA (GDPR Art. 28)?Published at /legal/dpa, no charge
Data on termination?Container and workspace volume deleted from the node, then the node is sanitised before reassignment. Filesystem deletion, not a cryptographic erase; export what you need before terminating, since it isn't reversible.

Questions we get from agencies

Is it safe to run candidate data through an LLM?

That depends on where the model runs and who can reach it, not on the model itself. On a GPUwerk dedicated instance in EU-Central, the machine is assigned to your agency alone and reachable only through your SSH keys; GPUwerk does not access, read, copy, index or analyse what runs on it except at your request for support or where a legal obligation requires it. This describes our infrastructure, not your obligations as a data controller for candidate personal data, which are for your own counsel to assess.

Does GPUwerk train on the CVs or candidate records we process?

No. GPUwerk operates infrastructure, not models. Candidate records are processed by software you install on your own instance, and under our data processing agreement GPUwerk does not access that content except at your request for support or where legally required. There is nothing for GPUwerk to train on.

Do you sign a DPA covering candidate personal data?

Yes, a standard GDPR Article 28 DPA is published at /legal/dpa at no charge. There are no sub-processors for instance workloads, listed at /legal/sub-processors.

Can one client's placement work see another client's candidate pool?

That's an application-level access control question your placement software should enforce, not something GPUwerk's infrastructure decides for you. The instance is single-tenant to your agency, so no other agency or vendor shares the GPU; separation between your own clients is up to how you structure the software running on it.

Related pages

Talk to us before you commit a workflow to it.

A short call covers what runs where, who can see it, and what your own data protection lead still needs to sign off on.

Talk to us Deploy an instance