LLM hosting a Norwegian personvernombud can sign off on.

Dedicated single-tenant infrastructure in EU-Central, operated by an EU entity with no US parent in the chain. Norway sits in the EEA rather than the EU, so it's worth being precise about how GDPR reaches Norwegian companies before assuming this page settles anything.

Not legal advice. This page describes GPUwerk's infrastructure and corporate structure. Whether it satisfies your specific obligations under Norwegian or EEA data protection law is a question for your own personvernombud or legal counsel, not for this website.

EEA, not EU: worth stating precisely

Norway is a member of the European Economic Area but not the European Union. GDPR itself is an EU regulation, but it was incorporated into Norwegian domestic law via the EEA agreement and given effect through the Norwegian Personal Data Act (personopplysningsloven). The practical result is that GDPR's rules apply in Norway in much the same way they do inside an EU member state, and the European Commission has recognised EEA/EFTA states as providing an adequate level of protection for transfer purposes. That said, the legal mechanism is different from straightforward EU membership, and GPUwerk isn't the right source to walk through the fine points of how the EEA route applies to your specific processing activity. If a transfer or scope question turns on that distinction for you, raise it with your own counsel before relying on anything below.

What a Norwegian buyer actually checks first

Before a pilot gets past IT, someone usually wants three things confirmed.

Where does the data sit?

On a dedicated machine in EU-Central, in the Czech Republic. Not a region toggle in a US console; a specific rack, run by a Societas Europaea registered in Prague with no US parent.

Who is the vendor, legally?

PRINT IT! SE. Company details, including the address and the competent supervisory authority for GPUwerk's own processing, are published at /legal/imprint. This is a Czech entity, not a Norwegian one, so GPUwerk itself is overseen by the Czech authority, not by Datatilsynet.

Can procurement get the paperwork?

Yes. A standard Art. 28 GDPR data processing agreement is at /legal/dpa, and there are no sub-processors on instance workloads, listed at /legal/sub-processors. No certifications such as ISO 27001 are claimed; if a specific one is a hard requirement for you, ask before assuming it applies.

For the compliance file

The facts to check against your own checklist.

QuestionAnswer
Operating entityPRINT IT! SE, Societas Europaea, Altajská 1568/2, Vršovice, 100 00 Praha 10, Czech Republic
Where is data physically processed?EU-Central, on a dedicated single-tenant machine assigned to you
Norway's own supervisory authorityDatatilsynet, for your own company's processing; not GPUwerk directly
US CLOUD Act exposure?None. No US parent, no US region, no US-incorporated entity in the chain.
Pricing$0.79/hour for a single DGX Spark, $1.79/hour for a two-node cluster (128GB unified memory each)
Who can access instance content?Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps standard infrastructure administrator access, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it.
Sub-processors for the workload?None, listed at /legal/sub-processors
DPA (Art. 28 GDPR)?Published at /legal/dpa, no charge
Certifications heldNone claimed, including ISO 27001. Confirm directly if your process requires one.

Questions we get from Norwegian buyers

Does GDPR apply to a Norwegian company using EU-Central hosting?

Norway is not an EU member but is part of the European Economic Area, and GDPR was incorporated into Norwegian law through the EEA agreement and the Norwegian Personal Data Act. In practice, GDPR's substantive rules apply in Norway much as they do in an EU member state, but the EEA route is a distinct legal mechanism, and how it interacts with your specific transfer or processing question is not something GPUwerk can assess. Confirm with your own counsel.

Which authority is responsible for data protection oversight?

GPUwerk is operated by PRINT IT! SE, registered in Prague, so the competent Czech supervisory authority applies to GPUwerk directly. Your own company's processing is separately overseen by Datatilsynet, the Norwegian Data Protection Authority. That's a question for your own personvernombud or legal counsel, not something GPUwerk can answer on your behalf.

Is a DPA available under Art. 28 GDPR?

Yes, published at /legal/dpa at no charge. There are no sub-processors for instance workloads, listed at /legal/sub-processors.

Is this legal advice?

No. This page describes GPUwerk's infrastructure and corporate structure. Whether it satisfies your specific compliance obligations under Norwegian or EEA law is a question for your own counsel.

Related pages

Send your personvernombud's questions our way.

We'll tell you plainly what's covered and what isn't, before it goes into a contract.

Talk to us Deploy an instance