Data Processing Agreement
Last updated 11 August 2026
This agreement applies where AyaiMQ processes personal data on your behalf as a processor under UK GDPR. It forms part of our Terms of Service. A signed copy is available on request for customers who need one.
1. Roles
Where you use AyaiMQ to transmit personal data through the broker, you are the controller and Logicboks is the processor. Each party will comply with its obligations under applicable data protection law, including UK GDPR.
2. Scope of processing
Subject matter: provision of a managed MQTT broker platform. Duration: for the term of your use of the service. Nature and purpose: hosting, transmitting, authenticating and logging MQTT connections and messages. Data subjects and categories: as determined by the Customer Data you choose to send.
3. Our obligations as processor
We will:
- Process personal data only on your documented instructions, including as set out in the Terms and this agreement.
- Ensure people authorised to process the data are bound by confidentiality.
- Apply appropriate technical and organisational security measures, as described on our Security page.
- Assist you, taking account of the nature of processing, with data subject requests and with your security, breach and impact assessment obligations.
- Notify you without undue delay after becoming aware of a personal data breach affecting your data.
- Delete or return personal data at the end of the service, unless we are required by law to retain it.
- Make available information needed to demonstrate compliance and allow for audits on reasonable notice.
4. Sub-processors
You authorise us to engage sub-processors to deliver the service, including our cloud and database provider (Supabase) and hosting infrastructure. We remain responsible for their performance and will give notice of intended changes so you can object on reasonable grounds.
5. International transfers
Where processing involves transfers outside the UK or EEA, we will ensure an appropriate safeguard is in place, such as an adequacy decision or standard contractual clauses.
6. Security
Our technical and organisational measures include encryption in transit, hashed broker credentials, per tenant isolation, row level access controls, and audit logging. These measures are described further on our Security page and may be updated to maintain an appropriate level of protection.
7. Contact
Data protection queries and requests under this agreement should be sent to privacy@ayaimq.com.