Data processing addendum
Click to Cockpit by Bryghton Media LLC · Effective October 1, 2026
Between the school or business that uses Click to Cockpit ("Customer", "you") and Bryghton Media LLC, a New York limited liability company ("Bryghton Media", "we"). Effective October 1, 2026.
This Data Processing Addendum ("DPA") is part of the Click to Cockpit Terms of Service ("Terms"). You accept it when you accept the Terms; no separate signature is needed. We’ll provide a countersigned copy on request.
1. Roles
- You are the controller / business. You decide why and how the personal information of your leads, students, contacts and team ("Customer Personal Data") is processed.
- We are your processor / service provider / contractor, as those terms are used in US state privacy laws (including the California Consumer Privacy Act as amended by the CPRA, and the Virginia, Colorado, Connecticut, Utah, Texas and similar laws, together "Privacy Laws").
- This DPA doesn’t cover information we collect as a controller for our own business (for example, your account owner’s billing details); our Privacy Policy covers that.
2. Details of processing
| Subject matter and purpose | Providing Click to Cockpit: storing and organizing leads and students, sending and receiving texts, emails and calls you set up, booking, reporting, AI-assisted features you switch on, support, security and backups. |
| Duration | The term of your subscription, plus the export and deletion period in section 9. |
| Types of data | Names, phone numbers, email addresses, messages and call details, notes, lead source and ad-click data, training progress, booking and payment records (amounts and dates, not card numbers), consent and opt-out records, website visit data from your tracking script, team members’ login and activity data. |
| Not to be uploaded | Social Security numbers, FAA medical details, passport/citizenship/TSA documents, license or certificate scans, full birth dates, card or bank numbers, health information, or other sensitive data the service isn’t built for. |
| People concerned | Your leads, prospective and current students (some may be under 18), parents or guardians, website visitors, and your staff. |
3. Our commitments
We will:
- Process Customer Personal Data only on your documented instructions (the Terms, this DPA, and how you configure and use Click to Cockpit), and tell you if we believe an instruction breaks the law.
- Not sell or share it (as Privacy Laws define those words), not use it for targeted advertising, and not retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing the service.
- Not combine it with personal information from other customers or our own sources, except as Privacy Laws allow a service provider to do.
- Make sure everyone who can access it is bound by confidentiality.
- Keep reasonable security measures (Annex A).
- Help you, by appropriate technical means, answer people’s requests to know, access, correct, delete or port their data, and with privacy assessments where Privacy Laws require.
- Tell you if we can no longer meet our obligations under Privacy Laws, and let you take reasonable steps to stop and fix unauthorized use.
- Not use it to train AI models, and not let our AI providers do so.
4. Subprocessors
You authorize the subprocessors on our Subprocessors page. Each is bound by a written contract (such as its data processing terms) that requires it to protect Customer Personal Data and use it only to provide its service to us, and we remain responsible for our obligations under this DPA. We’ll give at least 15 days’ notice (by email to the account owner and on that page) before adding or replacing a subprocessor. If you object on reasonable data-protection grounds and we can’t resolve it, you may cancel and get a prorated refund of prepaid fees for the affected service.
5. Security incidents
If we confirm a breach of security that leads to unauthorized access to, or loss, change or disclosure of, Customer Personal Data ("Security Incident"), we’ll notify you without undue delay, and no later than 72 hours after confirming it, with what we know (what happened, data affected, steps taken, a contact), and update you as we learn more. We’ll help you meet any notice duties you have to people or regulators. Notifying you isn’t an admission of fault or liability. Unsuccessful attempts that don’t compromise Customer Personal Data (for example, blocked logins, pings or port scans) aren’t Security Incidents.
6. Your responsibilities
You’ll: have a lawful basis and the consents needed to collect Customer Personal Data and to text, call and email the people in your account (see the Terms section 5 and the SMS Terms); give people any privacy notices the law requires; only instruct us to process data lawfully; and keep your logins secure.
7. Audits
We’ll answer reasonable written security questionnaires once a year and share summaries of our security practices. If a regulator requires it or after a confirmed security incident, you may audit our compliance with this DPA, at your cost, with 30 days’ notice, during business hours, without access to other customers’ data, under confidentiality. For subprocessors, we rely on their own audit reports (for example, SOC 2 reports where they publish them).
8. Where data is processed
Customer Personal Data is processed in the countries listed on the Subprocessors page (today the United States, Canada and Germany). We protect it the same way everywhere.
9. Return and deletion
You can export your leads at any time. After the subscription ends, we’ll give you a full export on request within 30 days, then delete Customer Personal Data from live systems; backup copies roll off on their normal schedule, within 30 days. We may keep data only where the law requires, and then only for that purpose.
10. Liability and order of precedence
Each side’s total liability under or relating to this DPA is subject to the exclusions and limits of liability in the Terms (sections 9 and 10), which apply in aggregate with all claims under the Terms, except where Privacy Laws don’t allow them to be limited. This DPA doesn’t give anyone other than you and us any rights. If this DPA and the Terms conflict about personal data, this DPA wins; otherwise the Terms govern.
Annex A: Security measures
- Each school’s data walled off from every other school’s by database row-level security on every table, with automated isolation tests.
- Encryption in transit (HTTPS/TLS) and at rest (provider-managed).
- 2-step login available for every user; role-based permissions inside each school.
- Secrets kept out of source code, in restricted server files; production access limited to the owner and named contractors.
- Audit log of sensitive actions (exports, deletions, permission changes).
- Daily backups by our database provider, with periodic restore checks.
- Automated tests and review of changes before release.
- Data minimization: the service is built not to hold the sensitive data listed in section 2.
- Automatic STOP/opt-out handling, quiet hours and stored consent proof for messaging.
- Incident-response steps for detecting, containing and notifying about Security Incidents.
Contact
Privacy and security questions: bryghton@bryghtonmedia.com