Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches

Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches
Natty Hatty Signature logo

Back

Security

icon

Natty Hatty — Data Breach Notification Policy

Version: v1.0

Effective Date: November 15, 2025

Natty Hatty, Inc. (“Natty Hatty”) prioritizes the security of all user data—especially the personal information of minors. This Data Breach Notification Policy outlines Natty Hatty’s procedures for identifying, assessing, responding to, and notifying users and authorities about data breaches, in accordance with applicable laws. This policy applies to all systems, employees, contractors, third-party service providers, and Organizations using Natty Hatty.

1. Definition of a Data Breach

A “data breach” is defined as: Any unauthorized access, acquisition, disclosure, alteration, or loss of personal data, whether accidental or malicious.

This includes:

  • Unauthorized access to minors’ personal information

  • Exposure of payment-related metadata

  • Compromise of accounts, passwords, tokens, or sessions

  • Access to signature audit logs or signed documents

  • Leaked rosters, team assignments, or event information

  • Loss of devices storing Restricted data

  • API misuse or scraping

  • Breach of third-party systems (AWS, Stripe, etc.) that impacts Natty Hatty

2. Data Breach Response Objectives

In the event of a breach, Natty Hatty will:

  • 1. Protect minors immediately

  • 2. Contain the incident

  • 3. Assess the scope and impact

  • 4. Notify affected parties as required

  • 5. Comply with all relevant breach laws

  • 6. Prevent future incidents

Protection of minor athletes is the primary objective.

3. Detection & Identification

Natty Hatty continuously monitors systems using:

  • Intrusion detection

  • IAM and access logs

  • AWS GuardDuty

  • Stripe fraud indicators

  • Rate-limiting / anti-bot protections

  • Anomaly detection

  • Incident Response playbooks

  • Audit logs (immutable)

Any employee, contractor, or customer may report suspected incidents to: security@nattyhatty.com

4. Incident Severity Classification

Natty Hatty categorizes breaches into:

4.1 Severity Level 1 — Critical

  • Exposure of minors’ personal data

  • Exposure of signatures, audit trails, or legal documents

  • Payment-related exposure (Stripe tokens, dispute logs, etc.)

  • System-wide compromise

4.2 Severity Level 2 — High

  • Unauthorized access to adult user personal data

  • Exposure of organization admin accounts

  • Access to rosters or schedules

4.3 Severity Level 3 — Medium

  • Limited account compromise

  • Improper internal access

  • Restricted API misuse

4.4 Severity Level 4 — Low

  • No personal data exposure

  • Attempted but unsuccessful breaches

Severity determines notification timelines.

5. Breach Containment Steps

Upon confirmation:

  • 1. Isolate affected systems

  • 2. Disable compromised accounts, tokens, API keys

  • 3. Revoke sessions or credentials

  • 4. Engage Natty Hatty’s Incident Response team

  • 5. Assess potential ongoing attack vectors

  • 6. Implement temporary protections (rate limits, WAF rules, etc.)

  • 7. Preserve logs & evidence (immutable audit logs)

6. Assessment & Impact Analysis

Natty Hatty determines:

  • What data was accessed

  • Whether minors’ data was involved (highest priority)

  • Whether payment or signature systems were affected

  • Number of users impacted

  • Whether data was copied or exfiltrated

  • Whether law enforcement must be notified

  • Required legal obligations state-by-state

7. Notification Requirements

Natty Hatty complies with:

  • CPRA (California Privacy Rights Act)

  • COPPA (Children’s Privacy)

  • HIPAA-aligned principles for medical/allergy data

  • All U.S. State Data Breach Notification Laws

  • GDPR-style guidelines (if applicable)

  • PCI-DSS requirements (if payment-related)

8. Notification Timelines

8.1 Notification to Affected Users

  • Without unreasonable delay

  • No later than 72 hours for minors’ data or high-risk breaches

  • Within state-mandated timelines (30–60 days depending on jurisdiction)

Notification includes:

  • Nature of the breach

  • Categories of affected data

  • Steps taken by Natty Hatty

  • Steps recommended for users

  • Contact information for follow-up

8.2 Notification to Organizations

Organizations will be informed as early as safely possible, especially involving rosters, players, or coaching accounts.

8.3 Notification to Authorities

  • State Attorneys General

  • CPRA enforcement agencies

  • FTC (for COPPA-related breaches)

  • Law enforcement (if minors are at risk)

  • Payment networks (if Stripe signals it)

  • Third-party vendors affected

8.4 Notification to Sub-Processors (Stripe, AWS, etc.)

Natty Hatty will report any vendor-related breach to the vendor’s security team for coordinated remediation.

9. Notification Method

Users may be notified via:

  • Email

  • In-app notification

  • SMS (if urgent and permitted)

  • Dashboard alerts (Organizations)

In extreme cases involving minor safety or imminent harm, Natty Hatty may escalate to:

  • Law enforcement

  • Child safety authorities

  • SafeSport (if appropriate)

10. Remediation Actions

Natty Hatty may take corrective actions including:

  • Password resets

  • Token/session invalidation

  • MFA reset or requirement

  • Forced logout across all devices

  • API/WAF rule updates

  • Patching vulnerable systems

  • Restoring from clean backups

  • Increasing monitoring thresholds

  • Improving encryption or access controls

11. Post-Incident Review

Within 7–14 days of resolution, Natty Hatty conducts:

  • A root cause analysis (RCA)

  • A security control review

  • A log-based reconstruction

  • A systemic improvement review

  • Updates to the Incident Response Plan

  • Updates to technical and administrative safeguards

A summary may be shared with impacted Organizations.

12. Data Breach Scenarios Covered

This Policy applies to:

  • Credential stuffing

  • Unauthorized access

  • Insider threats

  • Malicious actors

  • External hacking attempts

  • Data scraping

  • Exposed API keys

  • Misconfigured access controls

  • Storage bucket misconfigurations

  • Payment or signature system breaches

  • Third-party vendor incidents affecting Natty Hatty

13. Special Protections for Minors (COPPA Priority)

If a breach affects minors:

  • Notification is prioritized

  • Guardian contact is required

  • Law enforcement engagement is evaluated immediately

  • Data exposure is treated as Severity Level 1

  • Breach remediation is escalated to highest priority

  • Additional safety recommendations are provided

Natty Hatty enforces a zero-tolerance policy for any breach that risks harm to minors.

14. Contact

For breach notifications or suspected incidents:

security@nattyhatty.com

legal@nattyhatty.com

For urgent or high-risk concerns:
Subject Line: URGENT: SECURITY INCIDENT / POSSIBLE BREACH