EU COMPLIANCE

Your AI, under European law. Company, hardware and documents.

A Spanish company serving inference from its own hardware in Spain, with the documents your DPO will ask for: DPA, retention policy, model cards and subprocessors.

world map
Served from Spain · EU
The problem

Putting AI in production in Europe has three exits today. All three charge a toll.

01

Proprietary APIs. The real difference is price. They charge between 70% and 80% more per token than we do, so switching alone cuts a big chunk of your bill. Most of them also process outside the EU and train their models on what you send them.

OpenAIAnthropicGoogle
02

Hyperscalers. You depend on their GPU availability, and a reasonable price means a long-term rental. Deploying and operating the model yourself takes specialized knowledge, and you remain exposed to the CLOUD Act, since they are still US companies. We absorb that complexity.

AWSAzureGCP
03

US inference clouds. They are fast and good, but their compute runs outside the EU, in US data centers. And even if they opened a region in Europe, they would still be US companies: FISA and the CLOUD Act would reach them all the same, wherever their servers sit.

Together AIFireworks AIBaseten
No provider offers production-grade inference, below-market pricing, infrastructure in Spain and real physical deployment at once. That gap is where Nextbit exists.
Sovereignty

It is not enough for the server to be in Europe. The company has to be, too.

The US CLOUD Act compels any company incorporated under US law to hand over the data it controls, no matter where the servers physically are. An order addressed to a parent company in Delaware reaches a server in Paris.

01

We are a Spanish company. No US parent, subsidiary or controlling shareholder. The CLOUD Act and FISA 702 do not apply to us: it follows from where the company is incorporated.

02

Infrastructure in Spain. Our inference runs on our own hardware in Spain: company, hardware, location and jurisdiction, all European.

03

If anything runs outside, you will see it marked. Every model carries its origin badge in the catalog: before you integrate it, not after.

04

What we never do with your data. We never train, tune or evaluate any model on what you send us. On any plan, in any mode.

EUSpanish companyNo US parent companyGDPR · EU AI Act
Compliance

Compliance is not a badge. It is having the document when they ask for it.

DPA · CLOUD Act clause

DPA / Data processing agreement. Our processing agreement, with subprocessors, technical measures and a specific CLOUD Act / FISA 702 clause.

Retention: 90 d → 0 d

Data retention. We never train on your data. Operational data is deleted automatically after 90 days, or after 0 days if your Dedicated Inference agreement says so.

Model card · Art. 53

Model cards (EU AI Act Art. 53). Verified license, training-data summary and systemic-risk assessment for every model in the catalog.

Subprocessors in the DPA

Subprocessors. The subprocessor list is documented in the DPA and available in due diligence: provider, service and country.

Our customers sell to hospitals, banks and public administrations. Our compliance is a piece of theirs, so we document it as if we were the ones being audited.
Due diligence

Bring your DPO to the first call.

We go through the DPA, the subprocessors and where each model runs before you integrate anything.

Spanish companyNo US parent companyGDPR · EU AI Act