Policies

Data Processing Agreement

This agreement applies where AyaiMQ processes personal data on your behalf as a processor under UK GDPR. It forms part of our Terms of Service. A signed copy is available on request for customers who need one. If you are completing a Data Processing Impact Assessment, the DPIA information pack answers the questions this agreement does not.

Effective 21 August 2026

On this page 7 sections

1. Roles#

In short: You are the controller, we are the processor, for anything personal that passes through the broker.

Where you use AyaiMQ to transmit personal data through the broker, you are the controller and Logicboks Limited (registered in England and Wales, company number 13613888) is the processor. Each party will comply with its obligations under applicable data protection law, including UK GDPR.

One thing worth separating out, because it is the question a data protection officer asks first: for the personal data you send THROUGH the broker we are your processor, and that is what this agreement covers. For your own account and billing details we are the controller, and that is covered by the Privacy Policy instead.

2. Scope of processing#

In short: What we process, for how long, and on whose instructions.

Subject matter: provision of a managed MQTT broker platform. Duration: for the term of your use of the service. Nature and purpose: hosting, transmitting, authenticating and logging MQTT connections and messages. Data subjects and categories: as determined by the Customer Data you choose to send.

3. Our obligations as processor#

In short: Act on your instructions, keep it confidential, keep it secure, and help you answer requests.

We will:

  • Process personal data only on your documented instructions, including as set out in the Terms and this agreement.
  • Ensure people authorised to process the data are bound by confidentiality.
  • Apply appropriate technical and organisational security measures, as described on our Security page.
  • Assist you, taking account of the nature of processing, with data subject requests and with your security, breach and impact assessment obligations.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data.
  • Delete or return personal data at the end of the service, unless we are required by law to retain it.
  • Make available information needed to demonstrate compliance and allow for audits on reasonable notice.

4. Sub-processors#

In short: All of them named, with what they touch. We tell you before adding one.

You authorise us to engage the following sub-processors to deliver the service:

  • Supabase, database and authentication. Data is held in the EU.
  • Hetzner Online GmbH, which hosts the broker. The server is in Helsinki, Finland.
  • Lovable, which hosts the console and sends transactional email, using Mailgun's EU infrastructure to deliver it.
  • Cloudflare, which sits in front of the console as CDN and DDoS protection and terminates TLS for ayaimq.com, so it sees request metadata for console traffic. It is NOT in the path of MQTT traffic, which goes directly to the broker in Helsinki on ports 8883 and 8884.
  • Stripe Payments UK Limited, which processes payments and issues invoices. Stripe touches billing contact details only and never message payloads, so it is not a sub-processor of the Customer Data this agreement covers, and it is listed here so the picture is complete rather than because it processes anything you send through the broker.

We remain responsible for their performance. We will give you notice before adding or replacing a sub-processor so you can object on reasonable grounds.

5. International transfers#

In short: UK and EU only. We will not move your data outside that without telling you.

Where processing involves transfers outside the UK or EEA, we will ensure an appropriate safeguard is in place, such as an adequacy decision or standard contractual clauses.

6. Security#

In short: The measures on the security page, applied to your data as processor.

Our technical and organisational measures include encryption in transit, hashed broker credentials, per tenant isolation, row level access controls, and audit logging. These measures are described further on our Security page and may be updated to maintain an appropriate level of protection.

7. Contact#

In short: Where to send a data protection question, and the DPIA pack if you are assessing us.

Data protection queries and requests under this agreement should be sent to support@logicboks.com.

Questions about this document? Write to support@logicboks.com.