Back
Privacy — Data Governance
Natty Hatty Subprocessors – Natty Hatty Platform
Version: v1.0
Last Updated: November 15, 2025
This page identifies the authorized Subprocessors that Natty Hatty, Inc. (“Natty Hatty”) engages to support delivery of the Natty Hatty Platform, which includes:
Natty Hatty Business Center (Organization dashboard)
Natty Hatty Customer App (mobile app)
Platform-based roster tools, messaging, registrations, scheduling
Platform-integrated payment flows
Platform-level audit logs, authentication, and data processing
These Subprocessors may process Personal Data on behalf of Customers, as defined in our Data Processing Addendum (DPA).
Natty Hatty evaluates all Subprocessors for security, privacy, youth-safety, and regulatory compliance before engagement and on an ongoing basis.
Current Subprocessors for the Natty Hatty Platform
Amazon Web Services (AWS)
Hosting, storage, compute, backups — USA
Data: Customer account data, organization data, roster information, program data, encrypted documents, metadata, logs
Cloudflare
CDN, security layer, WAF, DDoS protection — USA
Data: IP addresses, network-level metadata, request logs
Stripe
Payment processing, payouts, disputes — USA
Data: Tokenized card data (handled directly by Stripe), payment metadata, billing information
Twilio / SendGrid
Email & SMS delivery — USA
Data: Email addresses, phone numbers, notification metadata
Managed SQL Database (Cloud Provider)
Relational database storage for platform data — USA
Data: Account data, roster information, registration data, platform metadata, event configuration data
Apple & Google (Mobile App Stores)
Mobile app distribution, crash logs, update delivery — Global
Data: App binary metadata, anonymous diagnostic logs
Important Notes
The Natty Hatty Platform does not store full card numbers, CVVs, or sensitive financial data.
Stripe processes all payment card information directly.
No biometric, advertising, or behavioral tracking data is collected from minors.
No Subprocessor is used for AI/ML model training.
No AI/ML Subprocessors
Natty Hatty does not use Artificial Intelligence (AI) or Machine Learning (ML) Subprocessors to process customer data within the Platform.
Data is never used for:
Model training
Profiling
Behavior prediction
Advertising technology
How We Add or Change Subprocessors
Consistent with our Data Processing Addendum (DPA):
1. Notification
Natty Hatty will provide 30 days’ advance notice of any new Subprocessor via:
Email
In-app notification
Or both
2. Customer Right to Object
Customers may object within 10 days on reasonable and specific data protection grounds.
3. Resolution Options
Work with the Subprocessor to address the concerns, or
Permit the Customer to terminate only the affected services with a pro-rated refund.
Natty Hatty always maintains full responsibility for ensuring Subprocessors provide protections consistent with our obligations under the DPA.
Data Protection & Security Requirements
All Natty Hatty Platform Subprocessors are contractually required to:
Process personal data only for the purpose of supporting Natty Hatty services
Maintain strong technical and organizational security controls
Protect youth and minor data in compliance with COPPA, CPRA, and other laws
Maintain compliance with relevant standards (SOC 2, ISO 27001, PCI-DSS, etc.)
Support deletion, correction, and access requests as permitted by law
Implement encryption in transit and at rest
Notify Natty Hatty promptly of any security incidents
Natty Hatty continually reviews Subprocessors for operational suitability, compliance, and risk.
Contact
For questions about these Subprocessors or to exercise rights under the DPA:
Subject line: “Subprocessors – Natty Hatty Platform”