LLM hosting a Romanian responsabil cu protecţia datelor can sign off on.

Dedicated single-tenant infrastructure in EU-Central, operated by an EU entity with no US parent in the chain, and the paperwork your data protection officer will ask for before anyone touches production data.

Not legal advice. This page describes GPUwerk's infrastructure, corporate structure, and contractual commitments. Whether it satisfies your specific obligations under Romanian or EU data protection law is a question for your own data protection officer or legal counsel, not for this website.

What a Romanian buyer actually checks first

Before a pilot gets past IT, someone usually wants three things confirmed.

Where does the data sit?

On a dedicated machine in EU-Central, in the Czech Republic. It's not a region toggle in a US console; it's a specific rack, and the operating company is a Societas Europaea registered in Prague with no US parent.

Who is the vendor, legally?

PRINT IT! SE. Company details, including the address and the competent supervisory authority for GPUwerk's own processing, are published at /legal/imprint. This is a Czech entity, not a Romanian one, so GPUwerk itself is not subject to oversight by the ANSPDCP, the same way any other EU-Central vendor you'd work with wouldn't be.

Can procurement get the paperwork?

Yes. A standard Art. 28 GDPR data processing agreement is at /legal/dpa, and there are no sub-processors on instance workloads, listed at /legal/sub-processors. No certifications such as ISO 27001 are claimed; if a specific one is a hard requirement for you, ask before assuming it applies.

Where this fits alongside outsourced IT

Romania has one of the larger IT and outsourcing sectors in the region, and a fair share of the companies running LLM pilots here are also the ones building or maintaining software for clients elsewhere in Europe. That changes what "private hosting" needs to mean in practice: it's not just your own data at stake, it's often a client's, under a contract that already specifies where processing can happen. A dedicated single-tenant Spark in EU-Central, with a published sub-processor list, is meant to be something you can point to in that kind of contract review without having to caveat it. Whether it actually satisfies a specific client's terms is still something to check clause by clause, not assume from this page.

The general landscape, stated plainly

Romania's data protection regulator is the ANSPDCP, the Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal. GPUwerk isn't in a position to tell you how the ANSPDCP's guidance applies to your particular workload, and this page doesn't attempt to. What GPUwerk can state factually: the infrastructure runs in EU-Central under an EU entity, GDPR and the EU AI Act apply to processing done there the same way they apply anywhere else in the Union, and a standard Art. 28 DPA is available so your own data protection officer can run their normal review. Beyond that, the specifics of Romanian implementing legislation and how it interacts with your particular use case are for your own counsel to work through, not a hosting vendor's marketing page.

For the compliance file

The facts to check against your own checklist.

QuestionAnswer
Operating entityPRINT IT! SE, Societas Europaea, Altajská 1568/2, Vršovice, 100 00 Praha 10, Czech Republic
Where is data physically processed?EU-Central, on a dedicated single-tenant machine assigned to you
US CLOUD Act exposure?None. No US parent, no US region, no US-incorporated entity in the chain.
Pricing$0.79/hour for a single DGX Spark, $1.79/hour for a two-node cluster (128GB unified memory each)
Who can access instance content?Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps standard infrastructure administrator access, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it.
Sub-processors for the workload?None, listed at /legal/sub-processors
DPA (Art. 28 GDPR)?Published at /legal/dpa, no charge
Certifications heldNone claimed, including ISO 27001. Confirm directly if your process requires one.

Questions we get from Romanian buyers

Where is the hardware located?

EU-Central, in the Czech Republic, within the same low-latency range most Romanian offices see from any EU-Central provider.

Which authority is responsible for data protection oversight?

GPUwerk is operated by PRINT IT! SE, registered in Prague, so the competent Czech supervisory authority applies to GPUwerk directly. Your own company's processing is separately overseen by the ANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal), Romania's data protection authority. That's a question for your own responsabil cu protecţia datelor, not something GPUwerk can answer on your behalf.

Is a DPA available under Art. 28 GDPR?

Yes, published at /legal/dpa at no charge. There are no sub-processors for instance workloads, listed at /legal/sub-processors.

Is this legal advice?

No. This page describes GPUwerk's infrastructure and corporate structure. Whether it satisfies your specific compliance obligations is a question for your own data protection officer or legal counsel.

Related pages

Send your DPO's questions our way.

We'll tell you plainly what's covered and what isn't, before it goes into a contract.

Talk to us Deploy an instance