# Hugging Face

## Kurzbeschreibung
**“The AI community building the future.”**


**Hugging Face **is not a single proprietary LLM provider, but a platform for hosting, discovering, distributing, evaluating, and deploying AI and LLM models. The Model Hub is used for storing, discovering, and using model checkpoints; LLMs can be used via Inference Providers, Inference Endpoints, or locally through libraries such as Transformers.

## Claim
LLM “The AI community building the future.”

## Geeignet für
- API Integration
- Automation / Workflows
- Education
- Data Analysis
- Data Extraction / Document Analysis
- Email / Communication
- Customer Service & Chatbots
- Programming / Software Development
- Research
- Writing & Editing
- Texts / Content
- Translations
- Science
- Knowledge Management / Internal Search

## Kernfunktionen
- Endpoints
- EU Storage
- Function Calling
- Inference
- LLM API
- MLOps
- Model Router
- Open Source LLMs
- PrivateLink
- Provider Switch
- SSO
- Structured Outputs

## Preismodell
- **free:** You can test API access with a free Hugging Face account. There are monthly free credits. According to the current Hugging Face documentation, free users receive monthly credits, currently listed as $0.10, subject to change. After that, you need additional credits or pay based on usage.
- **subscription:** **PRO **With Hugging Face PRO, you get significantly more included inference credits. The pricing page lists, among other things, 20× included inference credits for PRO; the Inference docs currently mention $2.00 in monthly credits for PRO users.


**Team & Enterprise** For organizations, there are Team and Enterprise. These plans also include Inference Provider benefits or credits per seat and enable centralized billing, limits, and administration. According to Hugging Face, Team/Enterprise organizations currently receive $2.00 per seat in monthly credits.
- **other:** **Pay-as-you-go** If your credits are used up, you can continue making API requests by purchasing additional credits or paying based on usage. The costs depend on the specific model, provider, and usage.


**Your own provider key **In some cases, you can also use your own API keys from external providers. In that case, billing does not go through Hugging Face, but directly through the respective provider; according to the documentation, Hugging Face does not charge for this call.

## DSGVO und Datenschutz
**Gesamteinschätzung:** Conditional

**On-prem / local hosting: partially**


Hugging Face can also be used via open-source libraries such as Transformers, Datasets, and Tokenizers. This opens up the possibility of a local or self-hosted solution, but a specific on-premise product page offering a complete enterprise solution on the customer’s own hardware was not explicitly mentioned on the pages reviewed.


**Private Cloud / Data Center: Partially**


Inference endpoints are described as dedicated, secure infrastructure; AWS PrivateLink is also recommended for private connectivity. This suggests isolated or controlled environments, but a general, explicit description of private cloud capabilities for the overall offering was not fully provided on the pages reviewed.


**EU SaaS / Managed: Covered**


EU storage regions are documented for Team and Enterprise organizations. The website explicitly states that EU companies can use the hub in compliance with the GDPR if datasets, models, and inference endpoints are stored in EU data centers. However, without a Team or Enterprise plan, repositories are located in the U.S. by default.


**Hybrid: Partially**


The website outlines a hybrid approach: open-source libraries for local use, plus the Hub, endpoints, and storage as managed services. Additionally, the storage page mentions the option of using a custom cluster. However, a formal hybrid product description is not explicitly labeled as such.


**AVV / DPA: Covered**


A GDPR Data Processing Agreement is explicitly mentioned on the website, though in the context of Enterprise or Enterprise Hub.


**No Training: Partially**


For Inference Provider Routing, it is explicitly stated that no user data is stored for training purposes. For Inference Endpoints, it is stated that payloads and tokens are not stored and that only logs are retained for 30 days. However, a platform-wide, general opt-out from AI training for all Hub services was not clearly specified on the pages found.


**Open Source / Transparency Path: Covered**


The open-source/transparency path is clearly documented: Hugging Face lists its own open-source libraries such as Transformers, Datasets, and Tokenizers; the platform positions itself as an open ML platform with open models, datasets, and Spaces. This creates a strong path toward technical transparency and greater autonomy.


**Data Processing**


When it comes to data processing, a distinction must be made between standard operation and configured Enterprise/Team usage. By default, according to the website, repositories for non-Team/non-Enterprise users are stored in the U.S. For Team and Enterprise users, storage regions can be set to the EU; the website lists models, datasets, and Spaces as applicable, and the compliance notice also includes inference endpoints. According to the documentation, inference endpoints do not store payloads or tokens, but they do retain logs for 30 days. When routing via inference providers, Hugging Face does not store either the request body or the response for training purposes, according to the documentation; at the same time, the website notes that external providers have their own security and data policies. The privacy policy also lists third-party providers and subprocessors in the U.S., France, and EMEA.


**Conclusion**


For an EU/EEA directory, Hugging Face should be rated “conditional” overall. The best available path to GDPR-compliant use is to utilize Team or Enterprise features with EU storage regions and, if applicable, an Enterprise DPA; additionally, the open-source path may enable local or self-managed use. However, standard SaaS usage is not consistently documented as EU-based, because the website specifies U.S. storage for non-Team/non-Enterprise repositories, and the general privacy policy lists U.S. servers and U.S. subprocessors.


**Sources**


- [https://huggingface.co/privacy](https://huggingface.co/privacy)
- [https://huggingface.co/docs/hub/main/storage-regions](https://huggingface.co/docs/hub/main/storage-regions)
- [https://huggingface.co/docs/hub/en/security](https://huggingface.co/docs/hub/en/security)
- [https://huggingface.co/docs/inference-endpoints/main/guides/security](https://huggingface.co/docs/inference-endpoints/main/guides/security)
- [https://huggingface.co/docs/inference-providers/main/security](https://huggingface.co/docs/inference-providers/main/security)
- [https://huggingface.co/docs/hub/storage-buckets-security](https://huggingface.co/docs/hub/storage-buckets-security)
- [https://huggingface.co/terms-of-service](https://huggingface.co/terms-of-service)

For users throughout the EU/EEA, GDPR-compliant use is generally possible according to the information provided on the website, but only under certain conditions. Positive aspects include the documented EU data residency for Team and Enterprise plans, the reference to GDPR-compliant use with datasets, models, and inference endpoints stored in EU data centers, and the availability of an AVV exclusively through the Enterprise plan. At the same time, the general privacy policy mentions the company’s servers in the U.S. and describes third-party providers and subprocessors, some of which are located in the U.S. For standard use without a Team or Enterprise plan, repositories are always stored in the U.S., according to the website. Therefore, use within the EU/EEA is not universally compliant with the GDPR, but is only compliant depending on the plan and configuration.


**Positive**


The website features several positive elements: EU storage regions for Team and Enterprise organizations; an explicit statement that EU companies can use the ML development hub in a GDPR-compliant manner with storage in EU data centers; DPA/AVV for Enterprise; SOC 2 Type 2; according to the documentation, inference endpoints do not store payloads or tokens, only logs for 30 days; according to the documentation, inference provider routing does not store request bodies or responses for training purposes.


**Negative**


The general privacy policy states that the company and its servers are located in the U.S. and that personal data may be processed in the U.S. or other countries. It also lists several subprocessors based in the U.S. According to the website, repositories for users outside of Team/Enterprise are always stored in the U.S. The website does not provide evidence of a blanket, universally applicable “EU-only” hosting policy. A general, platform-wide opt-out from AI training is not clearly stated on the website; it is only specified for certain inference services that user data is not stored for training purposes.


**Server Location**


Information presented inconsistently on the website: The privacy policy states that the company and its servers are located in the U.S. At the same time, Hugging Face documents EU storage regions for Team and Enterprise plans and specifies GDPR-compliant use for EU companies, with datasets, models, and inference endpoints located in EU data centers. The list of subprocessors/service providers includes, among others, the U.S., France, and EMEA; specific individual EU data center locations are not specified in more detail on the pages found.

## Hosting und Daten
- **On-Prem / lokales Hosting:** teilweise / indirekt
- **Private Cloud / Rechenzentrum:** teilweise / indirekt
- **EU SaaS / Managed:** abgedeckt
- **Hybrid:** teilweise / indirekt
- **AVV / DPA:** abgedeckt
- **Kein Training auf Kundendaten:** teilweise / indirekt
- **Open-Source / Transparenz-Pfad:** abgedeckt

## Standort
**Land:** France

**Taxonomie:** France

Hugging Face, Inc.: USA / Delaware Corporation; EU main establishment: Hugging Face SAS, 9 rue des Colonnes, 75002 Paris, France.

## Vorteile
- Very large LLM/model catalog with community, research, and enterprise models
- Unified API for many providers and model types
- OpenAI-compatible entry point for chat completions
- Dedicated Inference Endpoints for production deployments with autoscaling, logs, and metrics
- Strong open-source libraries such as Transformers, Datasets, Tokenizers, PEFT, TGI, and Safetensors
- Enterprise features such as SSO, RBAC, audit logs, resource groups, storage regions, and private repositories

## Nachteile
- Not a classic “one-model-from-a-single-vendor” LLM provider; quality, licensing, and governance depend heavily on the respective model.
- Community models and external providers require your own review of licensing, data protection, security, and model risks.
- Inference Providers forward requests to external providers via a proxy layer; their data protection and security terms must be reviewed separately.
- Pay-as-you-go and GPU-based usage can be difficult for beginners to estimate.
- Scale-to-zero can cause cold starts and is therefore not suitable for all real-time applications.

## Quellen
- Offizielle Website: https://huggingface.co/models

## Letzter Datenstand
2026-05-04

## Originalseite
https://kifox.ai/en/ki-tools/hugging-face-en/
