SOVEREIGNTY · GDPR · AI ACT

The question is not where the server is. It is who can compel it to be handed over.

The URL a CISO or a DPO forwards to their team. No badges we do not hold, no promises we cannot sign, and the legal exposure of each option laid out in a table.

The framework

What the CLOUD Act and FISA 702 are. Without the jargon.

CLOUD Act

It compels any company incorporated under US law to hand over the data it controls, wherever the servers are. An order served on a parent company in Delaware reaches a server in Paris. This is not hypothetical: in June 2025, Microsoft France told the French Senate it cannot guarantee that French data will not be seized by US authorities.

FISA 702

It lets US agencies order surveillance of non-US persons through communications providers under their jurisdiction, without notifying the person concerned. It applies because of who the provider is, not where the data sits.

Why the Data Privacy Framework does not solve it

The DPF covers commercial data processing, not government access. The EDPB itself confirms that contractual measures are not enough against surveillance legislation. The only structural answer is for the provider not to be subject to that jurisdiction, and that is not something you sign in a contract: it depends on where the company is incorporated.

The asset on this page

Exposure by deployment option.

OptionWho operates the hardwareUS jurisdiction?Guarantee
On-premise at your own siteYouNoMaximum: the data never leaves your building
Dedicated Inference / Capacity blockNextbit, in SpainNoHigh: Spanish company, own hardware, Spanish jurisdiction
ServerlessNextbit, in SpainNoHigh: with an explicit flag if any model were served outside the EU
Stack deployed in your own cloudYour cloud providerYour provider’sThe exposure is yours, not ours — you choose where
Commitments

What we promise. And what we do not.

We promise

A Spanish company with no US parent · our own hardware in Spain · we never train on customer data · EU/non-EU provenance flagged per model and queryable through the API · a DPA with a specific CLOUD Act and FISA 702 clause.

We do not promise

Absolute immunity from every jurisdiction on the planet, badges that have not been issued yet, or guarantees over the part of the chain you choose (your cloud, your devices). What we cannot sign, we do not say.

How the risk is reduced

Zero retention available by agreement on Dedicated Inference · BYOK and disk encrypted with your own key · real on-premise for the strictest case: the data never leaves your building.

Data retention. We never train on customer data. 90 days of operational retention by default, with automatic deletion. Zero retention available by agreement on Dedicated Inference.
GDPR and AI Act

Compliance is not putting up a badge. It is having the document when you are asked for it.

GDPR

Defined roles (data processor), a DPA covering sub-processors and technical measures, data-subject rights, support for your DPIA, and a 72-hour breach protocol. The list of sub-processors is documented in the DPA and available during due diligence.

AI Act

As a GPAI provider we publish a sheet per model (Art. 53): verified licence, training-data summary and risk assessment. And if your system is high-risk (recruitment, credit scoring, biometrics, clinical triage), your file needs traceability and control over the model that an opaque provider cannot give you.

EUDPA · CLOUD Act clauseArt. 53 sheets publishedSub-processors in the DPA
For your security team

Documentation under NDA.

The technical isolation architecture (hardware pinning, NUMA, IOMMU/ACS, NVLink partitioning, per-customer key encryption) is documented for your security team. Form → NDA → delivery. Request it. No ISO 27001 or ENS badges until they are issued. When they are, they will appear here with the certifying body, number and date.
Can a US authority demand my data from Nextbit?

The CLOUD Act and FISA 702 do not apply to us: that is not a negotiated clause, it follows from where the company is incorporated.

And if a model in the catalogue is served from outside the EU?

It is flagged as “Multi” in the table, on its sheet, in the playground and in the /api/models response — before you integrate it.

What if I deploy your stack in my own cloud?

The jurisdiction is your cloud provider’s: the exposure is yours and you choose where. We say exactly that in the table above.