LLM hosting your legal team can check off in one meeting.

Dedicated single-tenant infrastructure in EU-Central, operated by an EU entity with no US parent in the chain, and the paperwork your compliance team will ask for before production data touches it.

Not legal advice. This page describes GPUwerk's infrastructure, corporate structure, and contractual commitments. Whether it satisfies your specific obligations under Spanish or EU data protection law is a question for your own legal counsel, not for this website.

What a Spanish buyer actually checks first

Before a pilot clears procurement, someone usually wants three things confirmed.

Where does the data sit?

On a dedicated machine in EU-Central, in the Czech Republic. Not a region toggle in a US console, a specific rack, run by a Societas Europaea registered in Prague with no US parent anywhere in its ownership.

Who is the vendor, legally?

PRINT IT! SE. Company details, including the registered address and the competent supervisory authority for GPUwerk's own processing, are published at /legal/imprint. It's a Czech entity, so GPUwerk itself sits outside the AEPD's jurisdiction, the same way any other EU-Central provider you'd shortlist would.

Can procurement get the paperwork?

Yes. A standard Art. 28 GDPR data processing agreement is at /legal/dpa, and there are no sub-processors on instance workloads, listed at /legal/sub-processors. No certifications such as ENS or ISO 27001 are claimed; if one is a hard requirement for you, ask before assuming it applies.

The general landscape, stated plainly

Spain's national data protection authority is the Agencia Española de Protección de Datos (AEPD), though Catalonia, the Basque Country, and Andalusia each keep their own regional authority for processing within their scope. GPUwerk isn't in a position to tell you which one applies to your organisation, and this page doesn't attempt to. What can be stated as fact: the infrastructure runs in EU-Central under an EU entity, GDPR and the EU AI Act apply to processing done there the same way they apply anywhere in the Union, and a standard Art. 28 DPA is available so your own legal team can run its usual review. The Spanish implementing law, the LOPDGDD, adds a handful of national specifics on top of GDPR, particularly around employee monitoring and minors' consent. Working out how those apply to your specific use case is for your own counsel, not a hosting vendor's marketing page.

For the compliance file

The facts to check against your own checklist.

QuestionAnswer
Operating entityPRINT IT! SE, Societas Europaea, Altajská 1568/2, Vršovice, 100 00 Praha 10, Czech Republic
Where is data physically processed?EU-Central, on a dedicated single-tenant machine assigned to you
US CLOUD Act exposure?None. No US parent, no US region, no US-incorporated entity in the chain.
Pricing$0.79/hour for a single DGX Spark, $1.79/hour for a two-node cluster (128GB unified memory each)
Who can access instance content?Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps standard infrastructure administrator access, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it.
Sub-processors for the workload?None, listed at /legal/sub-processors
DPA (Art. 28 GDPR)?Published at /legal/dpa, no charge
Certifications heldNone claimed, including ENS or ISO 27001. Confirm directly if your process requires one.

Questions we get from Spanish buyers

Where is the hardware located?

EU-Central, in the Czech Republic. It's a longer flight than Frankfurt, but the traffic still stays inside the EU and inside GDPR's ordinary rules the whole way.

Which authority is responsible for data protection oversight?

GPUwerk is operated by PRINT IT! SE, registered in Prague, so the competent Czech supervisory authority applies to GPUwerk directly, not the AEPD. Your own company's processing is separately overseen by the AEPD, or by a regional authority if you're based in Catalonia, the Basque Country, or Andalusia. That's a question for your own legal or compliance team, not something GPUwerk can answer on your behalf.

Is a DPA available under Art. 28 GDPR?

Yes, published at /legal/dpa at no charge. There are no sub-processors for instance workloads, listed at /legal/sub-processors.

Is this legal advice?

No. This page describes GPUwerk's infrastructure and corporate structure. Whether it satisfies your specific compliance obligations is a question for your own legal counsel.

Related pages

Send your compliance team's questions our way.

We'll tell you plainly what's covered and what isn't, before it goes into a contract.

Talk to us Deploy an instance