Back
Privacy — Data Governance
NATTY HATTY — DATA PROCESSING ADDENDUM (DPA)
Last Updated: November 15, 2025 | Version: v1.0
This Data Processing Addendum (“DPA”) forms part of the Terms & Conditions, Master Services Agreement, or other written or electronic agreement (“Agreement”) between:
Natty Hatty, Inc. (“Natty Hatty,” “Processor,” “we,” “us,” or “our”)
and
Customer (“Controller,” “Customer,” “You,” or “Your”)
for the use of the Natty Hatty Signature platform (“Services”).
This DPA governs Natty Hatty’s Processing of Personal Data on behalf of Customer.
1. DEFINITIONS
1.1 “Personal Data” means any information relating to an identified or identifiable natural person processed by Natty Hatty on behalf of Customer.
1.2 “Processing” / “Process” means any operation performed on Personal Data.
1.3 “Controller” means Customer, who determines the purposes and means of processing.
1.4 “Processor” means Natty Hatty, who processes Personal Data on behalf of Customer.
1.5 “Subprocessor” means any third party engaged by Natty Hatty to process Personal Data.
1.6 “Data Protection Laws” means GDPR, UK GDPR, CCPA, CPRA, and all global privacy regulations.
1.7 “Standard Contractual Clauses (SCCs)” means the EU-approved data transfer clauses.
1.8 “End Users” means individuals whose Personal Data is processed by Natty Hatty on behalf of Customer.
2. ROLE OF THE PARTIES
2.1 Customer is the Controller.
2.2 Natty Hatty is the Processor.
2.3 Natty Hatty will process Personal Data only on documented instructions from Customer.
3. CUSTOMER INSTRUCTIONS
Natty Hatty will process Personal Data solely to:
Provide, maintain, support, and improve the Signature Product
Store and transmit Documents
Provide customer support
Comply with legal or regulatory obligations
Natty Hatty will not process Personal Data for any independent purpose.
4. NATTY HATTY’S OBLIGATIONS
Natty Hatty agrees to the following:
4.1 Process only under Customer instructions.
4.2 Maintain confidentiality of personnel.
4.3 Maintain appropriate technical and organizational security measures.
Including encryption, network security, access controls, monitoring, and backup systems.
4.4 Assist Customer with data subject rights.
Including access, deletion, correction, portability, and restriction.
4.5 Notify Customer of data breaches.
Without undue delay, and within 72 hours of becoming aware.
4.6 Maintain processing records as required by law.
5. CUSTOMER OBLIGATIONS
Customer must:
Provide lawful instructions
Ensure Personal Data is collected lawfully
Not upload prohibited or highly sensitive data unless legally required
Respond to data subject requests
Maintain Controller-level security measures
6. SUBPROCESSORS
6.1 Customer authorizes Natty Hatty to use Subprocessors required to provide the Services.
6.2 NOTICE & OBJECTION RIGHTS (UPDATED)
Natty Hatty will provide 30 days’ advance notice of any new Subprocessor via email or in-app notification.
Customer may object within 10 days, in writing, on reasonable and specific data protection grounds.
If Customer’s objection is valid, Natty Hatty will either:
Work with the Subprocessor to resolve the concern, or
Allow Customer to terminate the affected Services with a pro-rata refund.
6.3 Subprocessor Agreements
Natty Hatty shall ensure all Subprocessors:
Are bound by written contracts,
Provide equivalent data protections,
Process Personal Data only for authorized purposes.
6.4 Subprocessor List
Available at: 📍 nattyhatty.com/subprocessors
7. INTERNATIONAL DATA TRANSFERS
7.1 Natty Hatty may transfer Personal Data outside the EEA, Switzerland, or UK in compliance with Data Protection Laws.
7.3 STANDARD CONTRACTUAL CLAUSES (UPDATED)
For transfers from the EEA, Switzerland, or UK, the EU Standard Contractual Clauses (Module 2: Controller-to-Processor, 2021/914) are:
Incorporated by reference, and
Form part of this DPA, and
Binding on both parties.
The executed SCCs are included in Appendix 1. Customer appoints Natty Hatty as its agent to execute SCCs with Subprocessors where legally required.
8. DATA SUBJECT RIGHTS
Natty Hatty will assist Customer in fulfilling End User rights requests, including:
Access
Correction
Deletion
Objection
Restriction
Data portability
Customer is responsible for verifying identity.
9. SECURITY MEASURES
Natty Hatty maintains a written information security program including, at minimum:
Encryption at rest & in transit
Strict access controls & MFA
Secure development lifecycle
Intrusion detection
Backup & disaster recovery
Regular vulnerability scanning
10. PERSONAL DATA BREACH
Natty Hatty will:
Notify Customer within 72 hours of discovering a breach,
Provide all relevant information available,
Support investigations and remediation,
Assist with regulatory notifications when required.
11. DATA RETENTION & DELETION
Upon termination of the Services:
Natty Hatty will delete all Customer Data within 30 days,
Except where legal or audit obligations require retention,
Customer may request a data export prior to deletion.
Secure deletion methods will be used.
12. AUDITS
Customer may audit Natty Hatty’s compliance by:
Reviewing security certifications & reports (e.g., SOC 2, if applicable),
Requesting documentation,
Conducting remote assessments.
On-site audits:
Require reasonable notice,
Must not disrupt operations,
May incur reasonable fees.
13. LIABILITY
Liability under this DPA is subject to the limitation of liability in the main Agreement. Nothing in this DPA expands Natty Hatty’s liability beyond what is contractually agreed.
14. TERM & TERMINATION
This DPA remains in effect for as long as Natty Hatty processes Personal Data on behalf of Customer.
Sections requiring ongoing protection (confidentiality, data deletion, transfer mechanisms) survive termination.
15. MISCELLANEOUS
15.1 Conflict — If this DPA conflicts with the Agreement, this DPA governs for privacy matters.
15.2 Amendments — Natty Hatty may update this DPA to remain legally compliant. Continued use = acceptance.
15.3 Governing Law — Same governing law as the main Agreement (Delaware).
15.4 Assignment — Natty Hatty may assign this DPA in connection with merger, acquisition, or sale of assets.
APPENDIX 1 – STANDARD CONTRACTUAL CLAUSES (SCCs)
(Controller → Processor | EU 2021/914 | Module 2)
SECTION I
Clause 1 – Purpose and scope
(a) The purpose of these Clauses is to ensure compliance with Article 46(2)(c) of GDPR regarding international transfers of Personal Data.
Clause 2 – Effect and invariability
(a) These Clauses provide appropriate safeguards, enforceable data subject rights, and effective legal remedies.
📄 Full text available at:
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914
EXECUTION
By signing below, both parties agree that Appendix 1 constitutes the executed Standard Contractual Clauses.
Natty Hatty, Inc. (Processor)
By: ___________________________
Name: Legal Representative
Date: November 15, 2025
Customer (Controller)
By: ___________________________
Name: ___________________________
Date: ___________________________