BayqusDPA
İmkanlar Qiymət Başla Giriş
Giriş

Data Processing Agreement

Last updated: 17 July 2026 Forms part of the Terms of Service

This Data Processing Agreement (“DPA”) describes how Bayqus processes personal data on behalf of its customers when providing the Bayqus monitoring service. It supplements our Terms of Service and Privacy Policy, and applies to the extent Bayqus processes personal data that is subject to applicable data protection law. It is drafted to align with international data protection standards, including the EU GDPR. If there is a conflict, this DPA governs the processing of personal data. This DPA is governed by the laws of the Republic of Azerbaijan.

Bayqus is a product and trademark of ONYX (established 2019, onyx.az), the operator of the service. Full company registration details are available on request at support@bayqus.app.

1. Roles of the parties

For the personal data processed through the service:

  • The customer is the data controller — it determines the purposes and means of processing and is responsible for the lawful basis of the data it sends to Bayqus.
  • Bayqus is the data processor — it processes that data only to provide the monitoring service and only on the customer’s documented instructions.

Where a customer is itself an MSP acting as a processor for its own clients, Bayqus acts as a subprocessor and the same obligations apply down the chain.

2. Subject matter, nature & purpose

Subject matter. Provision of the Bayqus managed-IT monitoring service: collecting device health telemetry via an agent, storing it, evaluating alert rules, and presenting dashboards and alerts.

Nature and purpose. Processing (collection, storage, structuring, use, and deletion) of account and device telemetry for the sole purpose of monitoring the availability and health of the customer’s infrastructure and providing support.

Duration. Bayqus processes personal data for the term of the customer’s subscription and until data is deleted or returned as described in section 9. Metric history retention is plan-driven.

3. Types of data & data subjects

Categories of personal data

  • Account data: names, work email addresses, and login credentials of the customer’s users.
  • Device telemetry — health metrics only: online/offline status, CPU, RAM, disk per volume, uptime, network in/out, critical service up/down, disk I/O and SMART; inventory such as OS, hostname, IP address, and the active username; optionally antivirus status and pending updates. SNMP data from switches, printers, and UPS units (reachability, port up/down, traffic, toner/paper, battery/load).

What Bayqus does NOT collect: no keystroke logging, no screen capture, and no productivity or activity tracking. Health metrics only. See Security and Privacy Policy.

Categories of data subjects

The customer’s staff and administrators (as account users and as the active username on monitored endpoints), and any individuals associated with the customer’s monitored devices and endpoints.

4. Processor obligations

Bayqus will:

  • Process personal data only on the customer’s documented instructions, including the instructions set out in the Terms and this DPA, unless required otherwise by law (in which case Bayqus will inform the customer where legally permitted).
  • Ensure personnel authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (section 5).
  • Assist the customer, taking into account the nature of the processing, in responding to data-subject requests (access, correction, deletion, objection).
  • Assist the customer with security, breach notification, and data protection impact assessment obligations.
  • Not engage a subprocessor except as described in section 6.

5. Security measures

Bayqus maintains technical and organisational measures designed to protect personal data, including:

  • Encryption in transit: the agent connects via outbound TLS 1.2+ (MQTT over port 8884). No inbound port is opened on the customer side, and no VPN is required.
  • Access control: role-based access, per-device enrollment tokens for agent authentication, and least-privilege access to production systems.
  • Storage: data is stored in an access-restricted database on infrastructure in the EU and Azerbaijan.
  • Segregation & scoping: tenant data is scoped per customer.

See Security for a fuller description.

6. Subprocessors

The customer authorises Bayqus to engage subprocessors to help provide the service. Bayqus imposes data protection obligations on each subprocessor no less protective than those in this DPA and remains responsible for their performance. Current subprocessors:

SubprocessorPurposeLocation
Self-managed hostingCore hosting, infrastructure and databaseEU and Azerbaijan

Transactional and alert email is sent from ONYX / Bayqus infrastructure and is not delegated to a third-party email subprocessor.

Bayqus will give the customer at least 30 days’ notice by email of any intended addition or replacement of a subprocessor, giving the customer the opportunity to object on reasonable data-protection grounds.

7. Data location & international transfers

Personal data is hosted on self-managed infrastructure in the European Union and Azerbaijan; data residency is EU and Azerbaijan. Where processing involves a transfer across borders, Bayqus will rely on an appropriate legal transfer mechanism and safeguards consistent with international data protection standards.

Customers who require in-country data residency can run the Bayqus core on their own infrastructure (on-prem), keeping data sovereignty entirely on their side.

8. Personal data breach notification

Bayqus will notify the customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting the customer’s data. The notice will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed to address it.

9. Return & deletion of data

On termination or expiry of the subscription, Bayqus will, at the customer’s choice, delete or return the personal data it processes on the customer’s behalf, and delete existing copies, unless retention is required by law. During the subscription, metric history is retained on a plan-driven schedule and older data is deleted automatically as it ages out of the plan’s retention window. Following termination, Bayqus will delete or return the data within 30 days, unless retention is required by law.

10. Audit rights

Bayqus will make available to the customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted by the customer or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits, and conducted so as not to disrupt the service or compromise the security of other customers. Audits require reasonable notice of at least 30 days and may be conducted no more than once per year.

11. Contact

Data protection questions and requests under this DPA: support@bayqus.app — a single channel for all purposes. Full company registration details for ONYX are available on request at the same address.

Related: Privacy Policy Terms of Service SLA Security
BayqusManaged IT monitoring

Managed IT monitoring that sees behind NAT. The agent pushes out over TLS — without opening a single port.

Giriş

Məhsul

Ana səhifə NAT arxası İzolə sahələr Başla Status Agent konfiqurasiyası SNMP bələdçisi API monitorinqi

Müqayisə

vs UptimeRobot vs PRTG

Şirkət

Haqqımızda Dəstək Əlaqə

Hüquqi

Təhlükəsizlik Məxfilik Şərtlər SLA DPA
© 2026 Bayqus Managed IT monitoring platform