LLM hosting your privacy officer can actually check.
Dedicated single-tenant infrastructure in EU-Central, operated by an EU entity with no US parent in the chain, and a data processing agreement ready before the pilot starts, not after.
Not legal advice. This page describes GPUwerk's infrastructure, corporate structure, and contractual commitments. Whether it satisfies your specific obligations under Dutch or EU data protection law is a question for your own DPO or legal counsel, not for this website.
What a Dutch buyer checks before a pilot goes live
Most reviews at Dutch companies land on the same three questions, whether it's a scale-up or a bank.
Where does the data physically sit?
On a dedicated machine in EU-Central, in the Czech Republic. Not a dropdown in a US console, a specific rack, run by a Societas Europaea registered in Prague with no US parent.
Who's the vendor, and who regulates them?
PRINT IT! SE. Full company details, including the address and the competent supervisory authority for GPUwerk's own processing, are at /legal/imprint. It's a Czech entity, so the Autoriteit Persoonsgegevens isn't GPUwerk's regulator directly, the same as it wouldn't be for any vendor headquartered outside the Netherlands. Your own processing stays under AP oversight as usual.
Can we get the standard paperwork?
Yes. A standard Art. 28 GDPR DPA is at /legal/dpa, and there are no sub-processors on instance workloads, listed at /legal/sub-processors. No specific certifications are claimed; if one is a hard requirement for your project, ask directly rather than assuming it applies.
The general landscape, stated plainly
The Netherlands' data protection authority is the Autoriteit Persoonsgegevens, the reference point most Dutch companies use when assessing a vendor's compliance posture. GPUwerk isn't a Dutch entity and isn't directly supervised by the AP, but the processing it hosts happens inside the EU under GDPR regardless, the same as it would with any EU-Central provider. The EU AI Act applies to relevant use cases across the Union too, the Netherlands included. What GPUwerk can state as fact: EU-Central location, EU operating entity, no US parent, and a standard DPA available at no charge. Whether that's sufficient for a specific use case under Dutch implementing legislation (the UAVG) or any sector rule you fall under is for your own legal team to determine, not something a vendor's own page can settle.
For the compliance file
The facts to check against your own checklist.
| Question | Answer |
|---|---|
| Operating entity | PRINT IT! SE, Societas Europaea, Altajská 1568/2, Vršovice, 100 00 Praha 10, Czech Republic |
| Where is data physically processed? | EU-Central, on a dedicated single-tenant machine assigned to you |
| US CLOUD Act exposure? | None. No US parent, no US region, no US-incorporated entity in the chain. |
| Pricing | $0.79/hour for a single DGX Spark, $1.79/hour for a two-node cluster (128GB unified memory each) |
| Who can access instance content? | Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps standard infrastructure administrator access, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it. |
| Sub-processors for the workload? | None, listed at /legal/sub-processors |
| DPA (Art. 28 GDPR)? | Published at /legal/dpa, no charge |
| Certifications held | None claimed. Confirm directly if your process requires a specific one. |
Questions we get from Dutch buyers
Where is the hardware located?
EU-Central, in the Czech Republic. The operating entity, PRINT IT! SE, is a Societas Europaea registered in Prague, with no US parent, no US region, and no US-incorporated entity in the chain.
Does the Autoriteit Persoonsgegevens oversee GPUwerk?
No. GPUwerk is a Czech entity, so the competent Czech supervisory authority applies to GPUwerk's own processing, not the AP. Your own company's processing remains subject to the Autoriteit Persoonsgegevens as normal, the same as with any other EU-based vendor. Whether an arrangement satisfies your own obligations is a question for your own DPO or counsel.
Is a DPA available under Art. 28 GDPR?
Yes, published at /legal/dpa at no charge. There are no sub-processors for instance workloads, listed at /legal/sub-processors.
Is this legal advice?
No. This page describes GPUwerk's infrastructure and corporate structure. Whether it satisfies your specific obligations is a question for your own DPO or legal counsel.
Related pages
Send your privacy officer's checklist our way.
We'll tell you plainly what's covered and what isn't, before it goes into a contract.
Talk to us Deploy an instance