Hugging Face
GDPR Compliance
Data Handling
EU region available on Team and Enterprise plans. Inference Endpoints can be deployed on AWS or GCP EU regions. Models, datasets, and endpoints can be pinned to EU datacentres. Enterprise Hub storage regions feature available.
Payload data (prompts/tokens) not stored on Inference Endpoints. Logs retained 30 days.
Security documentation states Hugging Face does not store any customer data in terms of payloads or tokens. No training on inference endpoint data.
Certifications & EU AI Act
EU legal entity (HF SAS, Paris) is subject to EU AI Act as a provider. No formal certification published as of verification date.
Verification
Scope is Inference Endpoints (dedicated), NOT Inference Providers (shared/serverless). HQ: Hugging Face Inc. (New York, US). EU controller: Hugging Face SAS (Paris, France), supervised by CNIL. Sub-processors include OVHcloud (FR), AWS, GCP. EU residency and DPA require Team or Enterprise plan. Any model on the Hub can be deployed via Inference Endpoints.