Back
Security
Natty Hatty — Data Breach Notification Policy
Version: v1.0
Effective Date: November 15, 2025
Natty Hatty, Inc. (“Natty Hatty”) prioritizes the security of all user data—especially the personal information of minors. This Data Breach Notification Policy outlines Natty Hatty’s procedures for identifying, assessing, responding to, and notifying users and authorities about data breaches, in accordance with applicable laws. This policy applies to all systems, employees, contractors, third-party service providers, and Organizations using Natty Hatty.
1. Definition of a Data Breach
A “data breach” is defined as: Any unauthorized access, acquisition, disclosure, alteration, or loss of personal data, whether accidental or malicious.
This includes:
Unauthorized access to minors’ personal information
Exposure of payment-related metadata
Compromise of accounts, passwords, tokens, or sessions
Access to signature audit logs or signed documents
Leaked rosters, team assignments, or event information
Loss of devices storing Restricted data
API misuse or scraping
Breach of third-party systems (AWS, Stripe, etc.) that impacts Natty Hatty
2. Data Breach Response Objectives
In the event of a breach, Natty Hatty will:
1. Protect minors immediately
2. Contain the incident
3. Assess the scope and impact
4. Notify affected parties as required
5. Comply with all relevant breach laws
6. Prevent future incidents
Protection of minor athletes is the primary objective.
3. Detection & Identification
Natty Hatty continuously monitors systems using:
Intrusion detection
IAM and access logs
AWS GuardDuty
Stripe fraud indicators
Rate-limiting / anti-bot protections
Anomaly detection
Incident Response playbooks
Audit logs (immutable)
Any employee, contractor, or customer may report suspected incidents to: security@nattyhatty.com
4. Incident Severity Classification
Natty Hatty categorizes breaches into:
4.1 Severity Level 1 — Critical
Exposure of minors’ personal data
Exposure of signatures, audit trails, or legal documents
Payment-related exposure (Stripe tokens, dispute logs, etc.)
System-wide compromise
4.2 Severity Level 2 — High
Unauthorized access to adult user personal data
Exposure of organization admin accounts
Access to rosters or schedules
4.3 Severity Level 3 — Medium
Limited account compromise
Improper internal access
Restricted API misuse
4.4 Severity Level 4 — Low
No personal data exposure
Attempted but unsuccessful breaches
Severity determines notification timelines.
5. Breach Containment Steps
Upon confirmation:
1. Isolate affected systems
2. Disable compromised accounts, tokens, API keys
3. Revoke sessions or credentials
4. Engage Natty Hatty’s Incident Response team
5. Assess potential ongoing attack vectors
6. Implement temporary protections (rate limits, WAF rules, etc.)
7. Preserve logs & evidence (immutable audit logs)
6. Assessment & Impact Analysis
Natty Hatty determines:
What data was accessed
Whether minors’ data was involved (highest priority)
Whether payment or signature systems were affected
Number of users impacted
Whether data was copied or exfiltrated
Whether law enforcement must be notified
Required legal obligations state-by-state
7. Notification Requirements
Natty Hatty complies with:
CPRA (California Privacy Rights Act)
COPPA (Children’s Privacy)
HIPAA-aligned principles for medical/allergy data
All U.S. State Data Breach Notification Laws
GDPR-style guidelines (if applicable)
PCI-DSS requirements (if payment-related)
8. Notification Timelines
8.1 Notification to Affected Users
Without unreasonable delay
No later than 72 hours for minors’ data or high-risk breaches
Within state-mandated timelines (30–60 days depending on jurisdiction)
Notification includes:
Nature of the breach
Categories of affected data
Steps taken by Natty Hatty
Steps recommended for users
Contact information for follow-up
8.2 Notification to Organizations
Organizations will be informed as early as safely possible, especially involving rosters, players, or coaching accounts.
8.3 Notification to Authorities
State Attorneys General
CPRA enforcement agencies
FTC (for COPPA-related breaches)
Law enforcement (if minors are at risk)
Payment networks (if Stripe signals it)
Third-party vendors affected
8.4 Notification to Sub-Processors (Stripe, AWS, etc.)
Natty Hatty will report any vendor-related breach to the vendor’s security team for coordinated remediation.
9. Notification Method
Users may be notified via:
Email
In-app notification
SMS (if urgent and permitted)
Dashboard alerts (Organizations)
In extreme cases involving minor safety or imminent harm, Natty Hatty may escalate to:
Law enforcement
Child safety authorities
SafeSport (if appropriate)
10. Remediation Actions
Natty Hatty may take corrective actions including:
Password resets
Token/session invalidation
MFA reset or requirement
Forced logout across all devices
API/WAF rule updates
Patching vulnerable systems
Restoring from clean backups
Increasing monitoring thresholds
Improving encryption or access controls
11. Post-Incident Review
Within 7–14 days of resolution, Natty Hatty conducts:
A root cause analysis (RCA)
A security control review
A log-based reconstruction
A systemic improvement review
Updates to the Incident Response Plan
Updates to technical and administrative safeguards
A summary may be shared with impacted Organizations.
12. Data Breach Scenarios Covered
This Policy applies to:
Credential stuffing
Unauthorized access
Insider threats
Malicious actors
External hacking attempts
Data scraping
Exposed API keys
Misconfigured access controls
Storage bucket misconfigurations
Payment or signature system breaches
Third-party vendor incidents affecting Natty Hatty
13. Special Protections for Minors (COPPA Priority)
If a breach affects minors:
Notification is prioritized
Guardian contact is required
Law enforcement engagement is evaluated immediately
Data exposure is treated as Severity Level 1
Breach remediation is escalated to highest priority
Additional safety recommendations are provided
Natty Hatty enforces a zero-tolerance policy for any breach that risks harm to minors.
14. Contact
For breach notifications or suspected incidents:
security@nattyhatty.com
legal@nattyhatty.com
For urgent or high-risk concerns:
Subject Line: URGENT: SECURITY INCIDENT / POSSIBLE BREACH