Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches

Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches
Natty Hatty Signature logo

Back

Privacy — Data Governance

icon

NATTY HATTY — DATA PROCESSING ADDENDUM (DPA)

Last Updated: November 15, 2025 | Version: v1.0

This Data Processing Addendum (“DPA”) forms part of the Terms & Conditions, Master Services Agreement, or other written or electronic agreement (“Agreement”) between:

Natty Hatty, Inc. (“Natty Hatty,” “Processor,” “we,” “us,” or “our”)

and

Customer (“Controller,” “Customer,” “You,” or “Your”)

for the use of the Natty Hatty Signature platform (“Services”).

This DPA governs Natty Hatty’s Processing of Personal Data on behalf of Customer.

1. DEFINITIONS

1.1 “Personal Data” means any information relating to an identified or identifiable natural person processed by Natty Hatty on behalf of Customer.

1.2 “Processing” / “Process” means any operation performed on Personal Data.

1.3 “Controller” means Customer, who determines the purposes and means of processing.

1.4 “Processor” means Natty Hatty, who processes Personal Data on behalf of Customer.

1.5 “Subprocessor” means any third party engaged by Natty Hatty to process Personal Data.

1.6 “Data Protection Laws” means GDPR, UK GDPR, CCPA, CPRA, and all global privacy regulations.

1.7 “Standard Contractual Clauses (SCCs)” means the EU-approved data transfer clauses.

1.8 “End Users” means individuals whose Personal Data is processed by Natty Hatty on behalf of Customer.

2. ROLE OF THE PARTIES

2.1 Customer is the Controller.

2.2 Natty Hatty is the Processor.

2.3 Natty Hatty will process Personal Data only on documented instructions from Customer.

3. CUSTOMER INSTRUCTIONS

Natty Hatty will process Personal Data solely to:

  • Provide, maintain, support, and improve the Signature Product

  • Store and transmit Documents

  • Provide customer support

  • Comply with legal or regulatory obligations

Natty Hatty will not process Personal Data for any independent purpose.

4. NATTY HATTY’S OBLIGATIONS

Natty Hatty agrees to the following:

4.1 Process only under Customer instructions.

4.2 Maintain confidentiality of personnel.

4.3 Maintain appropriate technical and organizational security measures.

Including encryption, network security, access controls, monitoring, and backup systems.

4.4 Assist Customer with data subject rights.

Including access, deletion, correction, portability, and restriction.

4.5 Notify Customer of data breaches.

Without undue delay, and within 72 hours of becoming aware.

4.6 Maintain processing records as required by law.

5. CUSTOMER OBLIGATIONS

Customer must:

  • Provide lawful instructions

  • Ensure Personal Data is collected lawfully

  • Not upload prohibited or highly sensitive data unless legally required

  • Respond to data subject requests

  • Maintain Controller-level security measures

6. SUBPROCESSORS

6.1 Customer authorizes Natty Hatty to use Subprocessors required to provide the Services.

6.2 NOTICE & OBJECTION RIGHTS (UPDATED)

Natty Hatty will provide 30 days’ advance notice of any new Subprocessor via email or in-app notification.

Customer may object within 10 days, in writing, on reasonable and specific data protection grounds.

If Customer’s objection is valid, Natty Hatty will either:

  • Work with the Subprocessor to resolve the concern, or

  • Allow Customer to terminate the affected Services with a pro-rata refund.

6.3 Subprocessor Agreements

Natty Hatty shall ensure all Subprocessors:

  • Are bound by written contracts,

  • Provide equivalent data protections,

  • Process Personal Data only for authorized purposes.

6.4 Subprocessor List

Available at: 📍 nattyhatty.com/subprocessors

7. INTERNATIONAL DATA TRANSFERS

7.1 Natty Hatty may transfer Personal Data outside the EEA, Switzerland, or UK in compliance with Data Protection Laws.

7.3 STANDARD CONTRACTUAL CLAUSES (UPDATED)

For transfers from the EEA, Switzerland, or UK, the EU Standard Contractual Clauses (Module 2: Controller-to-Processor, 2021/914) are:

  • Incorporated by reference, and

  • Form part of this DPA, and

  • Binding on both parties.

The executed SCCs are included in Appendix 1. Customer appoints Natty Hatty as its agent to execute SCCs with Subprocessors where legally required.

8. DATA SUBJECT RIGHTS

Natty Hatty will assist Customer in fulfilling End User rights requests, including:

  • Access

  • Correction

  • Deletion

  • Objection

  • Restriction

  • Data portability

Customer is responsible for verifying identity.

9. SECURITY MEASURES

Natty Hatty maintains a written information security program including, at minimum:

  • Encryption at rest & in transit

  • Strict access controls & MFA

  • Secure development lifecycle

  • Intrusion detection

  • Backup & disaster recovery

  • Regular vulnerability scanning

10. PERSONAL DATA BREACH

Natty Hatty will:

  • Notify Customer within 72 hours of discovering a breach,

  • Provide all relevant information available,

  • Support investigations and remediation,

  • Assist with regulatory notifications when required.

11. DATA RETENTION & DELETION

Upon termination of the Services:

  • Natty Hatty will delete all Customer Data within 30 days,

  • Except where legal or audit obligations require retention,

  • Customer may request a data export prior to deletion.

Secure deletion methods will be used.

12. AUDITS

Customer may audit Natty Hatty’s compliance by:

  • Reviewing security certifications & reports (e.g., SOC 2, if applicable),

  • Requesting documentation,

  • Conducting remote assessments.

On-site audits:

  • Require reasonable notice,

  • Must not disrupt operations,

  • May incur reasonable fees.

13. LIABILITY

Liability under this DPA is subject to the limitation of liability in the main Agreement. Nothing in this DPA expands Natty Hatty’s liability beyond what is contractually agreed.

14. TERM & TERMINATION

This DPA remains in effect for as long as Natty Hatty processes Personal Data on behalf of Customer.

Sections requiring ongoing protection (confidentiality, data deletion, transfer mechanisms) survive termination.

15. MISCELLANEOUS

15.1 Conflict — If this DPA conflicts with the Agreement, this DPA governs for privacy matters.

15.2 Amendments — Natty Hatty may update this DPA to remain legally compliant. Continued use = acceptance.

15.3 Governing Law — Same governing law as the main Agreement (Delaware).

15.4 Assignment — Natty Hatty may assign this DPA in connection with merger, acquisition, or sale of assets.

APPENDIX 1 – STANDARD CONTRACTUAL CLAUSES (SCCs)

(Controller → Processor | EU 2021/914 | Module 2)

SECTION I

Clause 1 – Purpose and scope
(a) The purpose of these Clauses is to ensure compliance with Article 46(2)(c) of GDPR regarding international transfers of Personal Data.

Clause 2 – Effect and invariability
(a) These Clauses provide appropriate safeguards, enforceable data subject rights, and effective legal remedies.

📄 Full text available at:
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914

EXECUTION

By signing below, both parties agree that Appendix 1 constitutes the executed Standard Contractual Clauses.

Natty Hatty, Inc. (Processor)
By: ___________________________
Name: Legal Representative
Date: November 15, 2025

Customer (Controller)
By: ___________________________
Name: ___________________________
Date: ___________________________