A claims file is a medical record and a bank statement stapled together.
Process it on your machine.
Private LLM hosting on a dedicated machine in EU-Central, for insurers running claims triage, document extraction, or underwriting support on files that mix health, financial, and identity data in one bundle.
Not legal or compliance advice. This page describes GPUwerk's infrastructure and contractual commitments. Whether a specific claims or underwriting workflow has a valid legal basis under GDPR, including Article 9 for special-category data, is a decision for your own compliance function or counsel, not something an infrastructure page can settle.
Why claims and underwriting data doesn't fit the general answer
A single claims file can carry diagnosis codes, injury descriptions, bank details, and a policyholder's full identity, all in the same PDF. Underwriting files add income, health questionnaires, and sometimes family medical history. Most public AI tools are built for general text, not for a document type that triggers GDPR Article 9 and ordinary financial-data rules at the same time.
"The claims file goes into a shared API"
On a GPUwerk dedicated instance, the model runs on hardware assigned to your organisation alone, in EU-Central. GPUwerk operates the machine but, under the data processing agreement, does not access your content except at your request for support or where a legal obligation requires it. No claims adjuster's document passes through infrastructure shared with another insurer.
"Adjusters already summarize files in consumer AI tools"
Pasting a claims PDF into a public chat tool to get a quick summary is common and rarely sanctioned. A private instance with the same chat interface gives adjusters the workflow they already use, on hardware your organisation controls instead of a third party's. See the private ChatGPT setup →
"We need extraction, not just chat"
Structured extraction from scanned claims forms, ICD-coded diagnosis fields, or handwritten adjuster notes is a batch job as much as a conversation. Running it on a dedicated Spark means the extraction pipeline and the underlying documents stay on the same machine, with nothing round-tripping to an external API per document.
Underwriting has its own version of the problem
Underwriting files aren't claims files, but they carry a similar mix: income statements, health questionnaires, sometimes family medical history, all attached to an applicant who hasn't even become a policyholder yet. An underwriter asking a model to flag inconsistencies across a submitted application is a reasonable use of the technology. Doing it through a public API, where the applicant's income and health disclosures pass through infrastructure the insurer doesn't control, is a separate and avoidable decision. On a dedicated instance, that same workflow runs on hardware assigned to the insurer alone, with the underwriting file never leaving it.
What's actually in the contract
For your compliance officer or IT lead to review directly.
| Question | Answer |
|---|---|
| Where is data physically processed? | EU-Central, on a dedicated single-tenant machine assigned to your organisation |
| Who operates it? | PRINT IT! SE, a Societas Europaea registered in Prague, Czech Republic. No US parent entity. |
| Who can access instance content? | Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps infrastructure administrator access to the machine, as on any hosted service, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it. |
| Does GPUwerk read claims or underwriting documents? | No. We host the hardware and, under the DPA, do not access, read, copy, index or analyse workload content. |
| Sub-processors for the workload? | None, listed at /legal/sub-processors |
| DPA (GDPR Art. 28)? | Published at /legal/dpa, no charge |
| Data on termination? | Container and workspace volume deleted from the node, then the node is sanitised before reassignment. Filesystem deletion, not a cryptographic erase; export what you need before terminating, since it isn't reversible. |
Questions we get from insurers
Claims files often contain medical records. Does that change anything?
It raises the stakes but not the mechanics. Medical information inside a claims file is special-category data under GDPR Article 9, same as in a hospital record. GPUwerk's role is the same either way: EU-Central hardware, a dedicated single-tenant machine, an Article 28 DPA, and no access to your instance content. Whether a given claims workflow has a valid Article 9 basis is for your own DPO or counsel to confirm.
Does GPUwerk train on claims or underwriting data?
No. GPUwerk runs infrastructure, not models. Whatever you process on your dedicated instance is handled by software you install, behind SSH keys only you hold. Under the data processing agreement, GPUwerk does not access that content except at your request for support or where a legal obligation requires it, so there is nothing for us to train on.
Do you sign a DPA covering policyholder data?
Yes, a standard GDPR Article 28 DPA is published at /legal/dpa at no charge, and there are no sub-processors for instance workloads.
Can our compliance function review this before we commit a workflow?
Yes. We answer compliance questionnaires directly and can provide documentation on physical location, access controls, and deletion procedures. Email hello@gpuwerk.com.
Related pages
Bring your claims workflow to a machine you control.
Talk to the people who run the racks, or start with a pilot and a practical rollout plan.
Talk to us Deploy an instance