An important limitation, stated plainly
Running a model locally does not by itself make a deployment compliant with PDPL or any other regulation. Data residency is one input into a legal and security assessment that belongs to the client and their counsel. What local infrastructure does is make certain architectures possible; whether they are sufficient is a question I do not attempt to answer here.
Why run it internally first
Recommending an architecture I have not operated would be guessing. Running agents locally day to day shows me what benchmarks do not: what breaks, what is slow in practice, what maintenance actually costs, and which workloads quietly belong in the cloud after all.