On this page 11 sections
1. Who is responsible for your data#
In short: Logicboks Limited for your account, and you for anything you send through the broker.
Logicboks Limited is the data controller for the personal data described here. We are registered in England and Wales under company number 13613888, at B1 Vantage Park, Old Gloucester Road, Hambrook, Bristol, BS16 1GW, United Kingdom.
For questions or to exercise your rights, contact support@logicboks.com.
2. Data we collect#
In short: Account details, billing details, and connection logs. Never your card or bank numbers.
We collect the following categories of personal data:
- Account data: your name, email address, and organisation when you request access or create an account.
- Waitlist data: the email, name, company and use case you submit through the request access form.
- Usage and log data: broker connection events, IP addresses, timestamps and audit records generated when clients connect, publish or subscribe.
- Support data: information you provide when you contact us.
- Agreement records: which version of our terms, privacy policy and other documents you accepted, when, and the IP address and browser you accepted from. We keep this because you are entitled to know what you agreed to, and so are we.
- Billing data: your billing name and address, VAT number, purchase order reference, the plan you are on, and your invoice history. We do NOT hold your card or bank details at any point. Those are entered on Stripe's own pages and stay with Stripe.
3. Message payloads#
In short: We do not store them. The broker moves messages and forgets them, so there is no archive to ask us for.
AyaiMQ transmits the MQTT messages your devices publish and subscribe to. We do not inspect message payloads for our own purposes. Payloads may pass through and be temporarily buffered by the broker in order to deliver them. You are responsible for what you choose to send and should avoid placing unnecessary personal data in message payloads or topics.
4. How we use data#
In short: To run the service and bill you. No advertising, no profiling, and nothing sold on.
We use personal data to provide and operate the service, authenticate connections, enforce permissions, maintain security and audit trails, take payment, issue invoices, communicate with you about your account, and improve the service.
Our lawful bases are these. Running the service you subscribed to, taking payment for it, and emailing you about your own account are all CONTRACT. Keeping security and audit records, and keeping proof of what was agreed, are LEGITIMATE INTERESTS, namely protecting the platform and being able to answer a question about our own agreements. Keeping billing records for six years is a LEGAL OBLIGATION under UK tax law. We do not send marketing without asking separately first, and you can withdraw that at any time without it affecting your service.
Ticking the box at sign up is not consent in the GDPR sense and we do not treat it as such. It is you entering a contract, and it is why you cannot withdraw it and keep the service at the same time. Anything that genuinely is consent will always be a separate, unticked box.
5. Sharing and processors#
In short: Named in full, with what each one touches and where it is.
We share data with service providers who help us run AyaiMQ. Each of them acts as our processor under contract, and we do not sell personal data to anybody.
- Supabase, our database and authentication provider, which holds your account, your clusters and your credentials.
- Hetzner, which hosts the broker itself, in Finland.
- Stripe Payments UK Limited, which processes payments and issues invoices. Your billing name, address, VAT number and email are shared with Stripe so it can take payment and produce a valid VAT invoice. Card and bank details are given directly to Stripe and never reach us.
- Lovable, which hosts the console and sends our transactional email, using Mailgun's EU infrastructure to deliver it.
- Cloudflare, which sits in front of the console as CDN and DDoS protection and terminates TLS for ayaimq.com, so it sees request metadata for console traffic. It is not in the path of MQTT traffic, which goes directly to the broker in Finland.
If we add or change a processor we will update this list, and where you have a Data Processing Agreement with us we will give you notice so you can object.
6. International transfers#
In short: Your messages and stored data stay in the UK or the EU. Where an edge or payment provider processes anything further afield, a recognised safeguard covers it.
The broker, the database and email delivery all run in the UK or the EU, and your message data does not leave them. Two providers can process limited data more widely: Cloudflare handles console requests at the edge location nearest the visitor, so request metadata may be processed outside the UK or EEA, and Stripe is part of a US group. In each case the transfer is covered by an appropriate safeguard such as an adequacy decision or standard contractual clauses with the UK addendum, under that provider's data processing terms.
7. Retention#
In short: Connection logs 30 days, billing records six years because tax law requires it.
We keep account data for as long as your account is active and for a reasonable period afterwards. Connection and authentication logs are kept for 30 days and then deleted by a scheduled job; aggregate daily counts, which identify no individual, are kept longer so the console can draw a usage chart. Waitlist entries are kept until we have finished evaluating access.
Two things we keep for longer, and why. Billing records are kept for six years because UK tax law requires it, and we cannot delete them on request while that obligation stands. Records of which agreement you accepted are kept for as long as we might need to show what was agreed, which is normally the life of the contract plus six years.
8. Security#
In short: Encrypted in transit, isolated per tenant, credentials shown once and revocable instantly.
We protect data in transit with TLS, hash broker credentials, isolate each cluster, and apply row level access controls so customers can only see their own data. See our Security page for more detail.
9. Your rights#
In short: Access, correction, deletion and the rest, and one address to use for them.
Under UK GDPR you have rights to access, correct, delete, restrict, and port your personal data, and to object to certain processing. To exercise any of these, contact support@logicboks.com. You also have the right to complain to the Information Commissioner's Office.
10. Cookies#
In short: Only what is needed to keep you signed in. No advertising cookies.
We use a small number of cookies and similar technologies, described in our Cookie Policy.
11. Changes#
In short: We tell you before anything material changes.
We may update this policy. Material changes will be notified through the service or by email where appropriate.
Questions about this document? Write to support@logicboks.com.