Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches

Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches
Natty Hatty Signature logo

Back

Disclaimer

icon

Natty Hatty Signature — Audit Trail Policy

Last Updated: November 15, 2025

Version: v1.0

This Audit Trail Policy (“Policy”) explains how Natty Hatty, Inc. (“Natty Hatty,” “we,” “us,” or “our”) collects, records, preserves, and secures audit trail data for documents executed using Natty Hatty Signature (“Signature”). Audit trails are essential for validating electronic signatures and ensuring legal, regulatory, and evidentiary enforceability.

1. Purpose of the Audit Trail

The audit trail provides a verifiable, tamper-evident record of all significant actions taken on a document, including:

  • Signer identity

  • Signature events

  • Consent and intent

  • IP address and device data

  • Timestamps

  • Audit logs of access and activity

  • Cryptographic integrity checks

Audit trails support compliance with:

  • ESIGN Act (U.S.)

  • UETA (U.S.)

  • eIDAS SES (EU)

  • Best practices for digital evidence

2. What the Audit Trail Records

Natty Hatty Signature automatically records the following information for every document:

2.1 Signature Events

  • Signer’s name

  • Signer’s email address

  • Verification events (email delivery, open events, authentication)

  • Signature completion timestamp

  • Sequence of signing (if multiple signers)

  • Consent acceptance

2.2 IP Address & Device Information

For each event, the audit trail logs:

  • IP address

  • Device type (mobile, desktop, tablet)

  • Browser or OS fingerprint

  • Geolocation (approximate, if permitted)

This confirms attribution and intent.

2.3 Timestamps

Every event is timestamped with:

  • Date and time (UTC)

  • Event type (delivery, view, sign, decline, revoke)

  • Authentication attempts

  • Completion and locking of the document

Timestamps are immutable and essential for legal validity.

2.4 Document Hashing (Integrity Protection)

Natty Hatty generates a cryptographic hash of the final PDF and its signature data.

Hash includes:

  • Document content

  • Field placements

  • Signer inputs

  • Signature metadata

  • Audit trail snapshot

Integrity Guarantee:

If the final document is altered in any way, the hash will no longer match, proving tampering.

3. Log Integrity & Tamper Prevention

Natty Hatty uses multiple layers to ensure audit trails remain reliable.

3.1 Immutable Logging

All audit trail data is stored in an append-only, tamper-resistant format using:

  • Write-once log storage

  • Server-side hashing

  • Event-sequencing integrity checks

Natty Hatty employees cannot alter audit trails.

3.2 Secure Storage

Audit logs and documents are stored:

  • Encrypted at rest (AES-256)

  • Encrypted in transit (TLS 1.2+)

  • In AWS U.S. regions

  • With multi-zone redundancy

3.3 Tamper Detection

Every audit log entry is protected by:

  • Hash chains

  • Digital fingerprints

  • Server integrity validation

  • Signature locking once completed

If tampering is detected, the document is marked “Integrity Failed”.

4. Audit Trail Availability

4.1 Customers

Businesses (Controllers) may:

  • View audit trails

  • Download audit trails

  • Export them as part of the final signed PDF

4.2 Signers

Signers receive:

  • A downloadable copy of the signed document

  • Audit trail attached (where enabled)

  • Access via Customer App (if permitted by the organization)

5. Retention of Audit Trails

Audit trails are retained for the life of the Document and:

  • Retained up to 7 years after deletion when required for legal defense, fraud prevention, or compliance

  • Never deleted automatically unless the Customer account is terminated

(Full retention details: nattyhatty.com/legal/document-retention)

6. Legal Compliance

Audit trails are designed to support compliance with:

6.1 U.S. ESIGN Act Requirements

  • Intent to sign

  • Consent to electronic process

  • Attribution

  • Record retention

  • Accessibility

6.2 UETA Requirements

  • Electronic signatures legally equivalent to handwritten

  • Evidence of attribution

  • Reliable record retention

6.3 eIDAS (Simple Electronic Signatures – SES)

  • Signer identification evidence

  • Integrity of signed data

  • Event recording

Natty Hatty is not a qualified trust service provider (QES).

7. Customer Responsibilities

Customers are responsible for:

  • Verifying signer identity beyond electronic indicators

  • Understanding local laws applicable to their documents

  • Retaining backups if required by internal policies

  • Ensuring usage aligns with compliance needs

Natty Hatty provides the tools, but legal enforceability depends on jurisdiction.

8. Policy Changes

We may update this Policy as laws, standards, or platform capabilities evolve.

Material changes will be communicated to Customers.

9. Contact

For audit trail inquiries or legal questions:

  • Email:

    legal@nattyhatty.com

Subject: Audit Trail Policy Inquiry