LLM hosting a Portuguese encarregado de proteção de dados can sign off on.

Dedicated single-tenant infrastructure in EU-Central, operated by an EU entity with no US parent in the chain, and the paperwork your data protection officer will want before production data touches it.

Not legal advice. This page describes GPUwerk's infrastructure, corporate structure, and contractual commitments. Whether it satisfies your specific obligations under Portuguese or EU data protection law is a question for your own encarregado de proteção de dados or legal counsel, not for this website.

What a Portuguese buyer actually checks first

Before a pilot gets past IT or procurement, three questions tend to come up, whether you're a Lisbon fintech or a Porto engineering firm doing nearshore delivery for a client abroad.

Where does the data sit?

On a dedicated machine in EU-Central, in the Czech Republic. Latency from Lisbon or Porto is higher than from Frankfurt, but for most LLM workloads (chat, retrieval, document processing) the difference is not something end users notice.

Who is the vendor, legally?

PRINT IT! SE. Company details, including the address and the competent supervisory authority for GPUwerk's own processing, are published at /legal/imprint. This is a Czech entity, not a Portuguese one, so GPUwerk itself is not subject to oversight by the CNPD, the same way any other EU-Central vendor you'd work with wouldn't be.

Can procurement get the paperwork?

Yes. A standard Art. 28 GDPR data processing agreement is at /legal/dpa, and there are no sub-processors on instance workloads, listed at /legal/sub-processors. No certifications such as ISO 27001 are claimed; if one is a hard requirement for a specific client contract, ask before assuming it applies.

Nearshoring adds a second layer of questions

Portugal has become a base for teams delivering software and AI work to clients elsewhere in Europe and, increasingly, further afield. Lisbon and Porto both have a visible cluster of engineering shops doing exactly that. If you're one of them, the question your client asks isn't just "is this GDPR-compliant" but "where exactly does our data go once it leaves your laptops." An EU-Central instance under an EU entity is a straightforward answer to that: the data doesn't leave the Union, and it doesn't route through a US company's infrastructure along the way. Whether that satisfies a specific client's own data residency clause is something to check against the actual contract, not something this page can promise on your behalf.

The general landscape, stated plainly

Portugal's national supervisory authority is the CNPD (Comissão Nacional de Proteção de Dados), based in Lisbon, which oversees data protection compliance for companies established or processing data in Portugal. GPUwerk isn't a Portuguese entity and isn't overseen by the CNPD; it's overseen by the competent Czech authority instead, the same as any other EU-Central vendor. What GPUwerk can state factually: the infrastructure runs in EU-Central under an EU entity, GDPR and the EU AI Act apply to processing done there the same way they apply anywhere else in the Union, and a standard Art. 28 DPA is available so your own DPO can run their normal review. Beyond that, how Portugal's implementing legislation interacts with your specific use case is a question for your own counsel, not a hosting vendor's marketing page.

For the compliance file

The facts to check against your own checklist.

QuestionAnswer
Operating entityPRINT IT! SE, Societas Europaea, Altajská 1568/2, Vršovice, 100 00 Praha 10, Czech Republic
Where is data physically processed?EU-Central, on a dedicated single-tenant machine assigned to you
US CLOUD Act exposure?None. No US parent, no US region, no US-incorporated entity in the chain.
Pricing$0.79/hour for a single DGX Spark, $1.79/hour for a two-node cluster (128GB unified memory each)
Who can access instance content?Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps standard infrastructure administrator access, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it.
Sub-processors for the workload?None, listed at /legal/sub-processors
DPA (Art. 28 GDPR)?Published at /legal/dpa, no charge
Certifications heldNone claimed, including ISO 27001. Confirm directly if a client contract requires one.

Questions we get from Portuguese buyers

Where is the hardware located?

EU-Central, in the Czech Republic. It's a longer hop from Lisbon or Porto than from most of northern Europe, but it's still within the EU and subject to the same GDPR rules as any Portuguese data centre.

Which authority is responsible for data protection oversight?

GPUwerk is operated by PRINT IT! SE, registered in Prague, so the competent Czech supervisory authority applies to GPUwerk directly. Your own company's processing is separately overseen by the CNPD (Comissão Nacional de Proteção de Dados) in Lisbon, the way it would be regardless of which EU vendor you hosted with. That's a question for your own encarregado de proteção de dados, not something GPUwerk can answer on your behalf.

Is a DPA available under Art. 28 GDPR?

Yes, published at /legal/dpa at no charge. There are no sub-processors for instance workloads, listed at /legal/sub-processors.

Is this legal advice?

No. This page describes GPUwerk's infrastructure and corporate structure. Whether it satisfies your specific compliance obligations is a question for your own data protection officer or legal counsel.

Related pages

Send your DPO's questions our way.

We'll tell you plainly what's covered and what isn't, before it goes into a contract.

Talk to us Deploy an instance