The question is not where the server is. It is who can compel it to be handed over.
The URL a CISO or a DPO forwards to their team. No badges we do not hold, no promises we cannot sign, and the legal exposure of each option laid out in a table.
What the CLOUD Act and FISA 702 are. Without the jargon.
CLOUD Act
It compels any company incorporated under US law to hand over the data it controls, wherever the servers are. An order served on a parent company in Delaware reaches a server in Paris. This is not hypothetical: in June 2025, Microsoft France told the French Senate it cannot guarantee that French data will not be seized by US authorities.
FISA 702
It lets US agencies order surveillance of non-US persons through communications providers under their jurisdiction, without notifying the person concerned. It applies because of who the provider is, not where the data sits.
Why the Data Privacy Framework does not solve it
The DPF covers commercial data processing, not government access. The EDPB itself confirms that contractual measures are not enough against surveillance legislation. The only structural answer is for the provider not to be subject to that jurisdiction, and that is not something you sign in a contract: it depends on where the company is incorporated.
Exposure by deployment option.
| Option | Who operates the hardware | US jurisdiction? | Guarantee |
|---|---|---|---|
| On-premise at your own site | You | No | Maximum: the data never leaves your building |
| Dedicated Inference / Capacity block | Nextbit, in Spain | No | High: Spanish company, own hardware, Spanish jurisdiction |
| Serverless | Nextbit, in Spain | No | High: with an explicit flag if any model were served outside the EU |
| Stack deployed in your own cloud | Your cloud provider | Your provider’s | The exposure is yours, not ours — you choose where |
What we promise. And what we do not.
We promise
A Spanish company with no US parent · our own hardware in Spain · we never train on customer data · EU/non-EU provenance flagged per model and queryable through the API · a DPA with a specific CLOUD Act and FISA 702 clause.
We do not promise
Absolute immunity from every jurisdiction on the planet, badges that have not been issued yet, or guarantees over the part of the chain you choose (your cloud, your devices). What we cannot sign, we do not say.
How the risk is reduced
Zero retention available by agreement on Dedicated Inference · BYOK and disk encrypted with your own key · real on-premise for the strictest case: the data never leaves your building.
Compliance is not putting up a badge. It is having the document when you are asked for it.
GDPR
Defined roles (data processor), a DPA covering sub-processors and technical measures, data-subject rights, support for your DPIA, and a 72-hour breach protocol. The list of sub-processors is documented in the DPA and available during due diligence.
AI Act
As a GPAI provider we publish a sheet per model (Art. 53): verified licence, training-data summary and risk assessment. And if your system is high-risk (recruitment, credit scoring, biometrics, clinical triage), your file needs traceability and control over the model that an opaque provider cannot give you.
Documentation under NDA.
Can a US authority demand my data from Nextbit?
The CLOUD Act and FISA 702 do not apply to us: that is not a negotiated clause, it follows from where the company is incorporated.
And if a model in the catalogue is served from outside the EU?
It is flagged as “Multi” in the table, on its sheet, in the playground and in the /api/models response — before you integrate it.
What if I deploy your stack in my own cloud?
The jurisdiction is your cloud provider’s: the exposure is yours and you choose where. We say exactly that in the table above.