Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches

Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches
Natty Hatty Signature logo

Back

Privacy — Data Governance

icon

Natty Hatty — Standard Contractual Clauses (SCCs)

Version: v1.0

Last Updated: November 15, 2025

Last Reviewed: November 15, 2025

Natty Hatty, Inc. (“Natty Hatty”) uses the EU Standard Contractual Clauses (SCCs) as the legal mechanism for transferring personal data from the European Economic Area (EEA), Switzerland, and the United Kingdom to the United States in connection with our Signature digital-signature platform and other Natty Hatty services.

The SCCs are incorporated into our Data Processing Addendum (DPA) and apply automatically to any Customer who transfers Personal Data to Natty Hatty from the EEA, Switzerland, or UK.

1. What Are Standard Contractual Clauses (SCCs)?

The SCCs are pre-approved legal safeguards issued by:

  • The European Commission (for EU/EEA transfers)

  • The UK ICO Addendum (for UK transfers)

  • The Swiss FDPIC (for Swiss transfers)

They ensure that personal data transferred outside the EEA/UK receives a level of protection consistent with GDPR.

Natty Hatty complies with SCCs Module 2 (Controller → Processor), 2021/914.

2. When Do SCCs Apply?

SCCs apply automatically when:

  • A Customer located in the EEA/UK/Switzerland uses Natty Hatty services, and

  • Personal Data is transferred to the United States or a country without “adequacy” status.

No additional signatures are required.

No additional forms are required.

By using Natty Hatty, the SCCs are automatically in effect.

3. Incorporation into the DPA

Our Data Processing Addendum (DPA) incorporates SCCs by reference.

Specifically:

For international transfers from the EEA, Switzerland, or UK, the EU Standard Contractual Clauses (Module 2: Controller-to-Processor, 2021/914) are automatically incorporated into this DPA and form a binding part of Customer’s Agreement with Natty Hatty.

The DPA also includes:

  • The UK ICO Addendum

  • Swiss-specific transfer terms

  • Enforcement, third-party beneficiary rights

  • Mandatory SCC appendices

📄 View Natty Hatty DPA:
https://nattyhatty.com/dpa

4. SCCs Execution (Appendix 1)

Natty Hatty provides a pre-executed SCC Appendix for Customer convenience.

Customers do not need to countersign unless their internal compliance requires a wet signature.

Executed SCC Header (Controller → Processor)

  • Clauses: EU SCCs (2021/914), Module 2

  • Data Exporter: Customer (Controller)

  • Data Importer: Natty Hatty, Inc. (Processor)

  • Date: November 15, 2025 (Natty Hatty execution date)

📄 Download Appendix 1 (SCC Execution Page)
(A downloadable PDF version can also be generated if you want it.)

5. Which SCC Version Does Natty Hatty Use?

Natty Hatty uses the most current and legally valid SCC framework:

  • ✔️ EU SCCs (2021/914) – Module 2 (Controller→Processor)

  • ✔️ UK Addendum (International Data Transfer Addendum to the EU SCCs)

  • ✔️ Swiss FDPIC Addendum (alignment with Swiss Federal Act on Data Protection)

This ensures legal compatibility with:

  • GDPR (EU 2016/679)

  • UK GDPR & Data Protection Act 2018

  • Swiss FADP

  • CPRA (California) for onward transfers

6. Subprocessors & International Transfers

Natty Hatty maintains a publicly available list of all third-party Subprocessors involved in providing Signature.

Each Subprocessor:

  • Is contractually bound to SCC-equivalent protections

  • Processes data only for permitted purposes

  • Undergoes reviews for privacy & security compliance

📄 View Subprocessors Page:
https://nattyhatty.com/subprocessors

7. Commitment to Data Protection

Natty Hatty implements a wide range of legal, technical, and organizational safeguards to ensure data transferred under SCCs remains protected, including:

  • Encryption at rest and in transit

  • Access control & least privilege policy

  • Secure development lifecycle (SDLC)

  • Continuous monitoring & intrusion detection

  • DPA + SCC compliance audit support

  • Incident response protocols

  • 72-hour breach notification commitments

Natty Hatty does not sell, rent, or reuse customer Personal Data for any purpose other than providing the services.

8. Transparency Statement

Natty Hatty does not rely on:

  • Derogations

  • Consent as a transfer mechanism for EU data

  • Data sharing for advertising

  • AI/ML data processing by third parties

No AI/ML Subprocessors are used for customer data.

9. Contact Information

For privacy, data transfer, or SCC-related inquiries, contact us at:

Natty Hatty, Inc. — Privacy Office

legal@nattyhatty.com

📬 Subject Line: “SCCs Inquiry”

We respond to all legally valid SCC inquiries promptly.