Where the data goes with a hosted API
When an employee pastes a customer email into a hosted model, that personal data is transferred to the provider, often outside the EU. You then need a data processing agreement, a transfer mechanism and a clear retention story for every provider in the chain.
This guide explains how the architecture changes the picture. It is not legal advice; check your specific case with your DPO.
What changes when the model runs on your GPU
- Processing location: inference happens on the GPU you choose, for example a server in Germany or Finland, or in your own office.
- Model provider: open-weight models run locally, so the model vendor never sees your prompts.
- Retention: you decide what is logged on your machines.
What gpuos itself processes
gpuos is built and hosted in the EU. API requests pass through the gpuos gateway, which forwards them to your node over the agent's outbound connection and streams the answer back.
| Data | Stored by gpuos? |
|---|---|
| Prompt and completion text | No, only relayed |
| Token counts, latency, status, model, key, node | Yes, for usage metering |
| Account data: name, email, workspace members | Yes |
| Model weights | No, they live on your node |
Checklist
- List gpuos as a processor for account and metering data in your records of processing.
- Document where your GPU nodes are located.
- Create one API key per application so you can trace and revoke access.
- Prefer licenses that allow commercial use without restrictions (Apache 2.0, MIT); every model page shows its license.