Private LLM hosting for Icelandic teams, under the same GDPR rules you already follow.
Dedicated single-tenant infrastructure in EU-Central, run by a Czech Societas Europaea. Iceland applies GDPR through the EEA Agreement, so a data flow between Reykjavík and Prague is intra-EEA, not a cross-border transfer requiring standard contractual clauses.
Not legal advice. This page describes GPUwerk's infrastructure and corporate structure. Whether it satisfies your specific obligations under Icelandic or EU/EEA data protection law is a question for your own lögfræðingur or data protection officer, not for this website.
EEA, not a third country
Iceland is not an EU member state, but it is part of the European Economic Area, and the EEA Joint Committee decision incorporating the GDPR into the EEA Agreement has applied in Iceland since 2018. Iceland's Act on Data Protection and the Processing of Personal Data, nr. 90/2018, transposes it into domestic law. In practice, this means a hosting vendor in the Czech Republic, an EU member state, is not a third country from Iceland's perspective. There's no adequacy decision to check and no standard contractual clauses to attach; the transfer rules that apply within the EU apply the same way here.
Where does the data sit?
On a dedicated machine in EU-Central, in the Czech Republic, inside the EEA's common data protection framework.
Who is the vendor, legally?
PRINT IT! SE, a Czech Societas Europaea. Company details are published at /legal/imprint.
Can procurement get the paperwork?
Yes. A standard Art. 28 GDPR data processing agreement is at /legal/dpa, and there are no sub-processors on instance workloads, listed at /legal/sub-processors. No certifications such as ISO 27001 are claimed; confirm directly if one is a requirement for you.
Two authorities, one framework
Your own company's processing in Iceland is supervised by Persónuvernd, the Icelandic Data Protection Authority. GPUwerk is operated by PRINT IT! SE, registered in Prague, so GPUwerk's processing falls under the Czech Office for Personal Data Protection (ÚOOÚ). That's a normal EEA arrangement: each entity answers to its own national authority, and both authorities apply the same GDPR text. What changes for an Icelandic buyer compared to, say, a US vendor is that there's no separate adequacy question to resolve and no CLOUD Act exposure through a US parent, because there isn't one in this chain. This still isn't a substitute for your own review: whether GPUwerk's setup satisfies your sector rules or internal policy is a question for your own counsel or DPO.
For the compliance file
The facts to check against your own checklist.
| Question | Answer |
|---|---|
| Operating entity | PRINT IT! SE, Societas Europaea, Altajská 1568/2, Vršovice, 100 00 Praha 10, Czech Republic |
| Where is data physically processed? | EU-Central, on a dedicated single-tenant machine assigned to you |
| Transfer basis Iceland → Czech Republic | Intra-EEA. GDPR applies in Iceland via the EEA Agreement (in force since 2018); no SCCs needed for this leg. |
| Supervisory authority for your own processing | Persónuvernd (Iceland) |
| Supervisory authority for GPUwerk | Úřad pro ochranu osobních údajů (ÚOOÚ), as the vendor is a Czech entity |
| US CLOUD Act exposure? | None. No US parent, no US region, no US-incorporated entity in the chain. |
| Pricing | $0.79/hour for a single DGX Spark, $1.79/hour for a two-node cluster (128GB unified memory each) |
| Who can access instance content? | Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps standard infrastructure administrator access, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it. |
| Sub-processors for the workload? | None, listed at /legal/sub-processors |
| DPA (Art. 28 GDPR)? | Published at /legal/dpa, no charge |
| Certifications held | None claimed, including ISO 27001. Confirm directly if your process requires one. |
Questions we get from Icelandic buyers
Does GDPR actually apply if Iceland isn't in the EU?
Yes. Iceland is in the European Economic Area, not the EU, and the EEA Joint Committee incorporated the GDPR into the EEA Agreement, in force in Iceland since 2018. Iceland's own data protection act, nr. 90/2018, implements it domestically. For a hosting decision, moving data between Iceland and the Czech Republic is intra-EEA, not a third-country transfer.
Who is the supervisory authority?
For your own company's processing, Persónuvernd, the Icelandic Data Protection Authority. GPUwerk is operated by PRINT IT! SE, a Czech entity, so GPUwerk's own processing is supervised by the Czech Office for Personal Data Protection (ÚOOÚ). The two authorities cooperate under the same GDPR framework, and Persónuvernd is your point of contact regardless of where a vendor sits.
Is a DPA available under Art. 28 GDPR?
Yes, published at /legal/dpa at no charge. There are no sub-processors for instance workloads, listed at /legal/sub-processors.
Is this legal advice?
No. This page describes GPUwerk's infrastructure and corporate structure. Whether it satisfies your specific compliance obligations is a question for your own lögfræðingur or data protection officer.
Related pages
One framework, no adequacy question.
EEA to EU, same rules throughout.
Talk to us Deploy an instanceSee how this compares for other EEA and EU countries: Malta, Cyprus, Latvia, Lithuania. For the general case, see private LLM hosting and pricing.