Back
Security
Natty Hatty — Data Classification Policy
Version: v1.0
Effective Date: November 15, 2025
Natty Hatty, Inc. (“Natty Hatty”) classifies all data it processes to ensure appropriate protection, access control, retention, and handling. Because Natty Hatty manages youth-sports data—including minors’ information—this policy defines strict standards that govern how sensitive data must be secured.
This Data Classification Policy applies to:
Natty Hatty employees
Contractors
Infrastructure systems
APIs and integrations
All organizations using Natty Hatty’s platform
1. Data Classification Categories
Natty Hatty uses a four-tier classification model:
Restricted Data (Tier 1 — Highest Sensitivity)
Confidential Data (Tier 2)
Internal Data (Tier 3)
Public Data (Tier 4 — Lowest Sensitivity)
Each category has defined storage, access, handling, and transmission rules.
2. Tier 1 — Restricted Data
Highest sensitivity — strict security controls required.
Restricted Data includes any information that could:
Identify or endanger a minor
Impact payment security
Cause legal, financial, or compliance harm if exposed
Affect youth-sports safety
Examples of Restricted Data
2.1 Minors’ Personal Information (COPPA-Regulated)
Full name of a minor
Date of birth
Guardian relationships
Contact information
Player profile details
Attendance, roster, or team assignments
Medical/allergy notes (if entered)
2.2 Payment & Financial Data
Payment tokens (Stripe)
Last 4 of card numbers
Transaction metadata
Refund/dispute logs
Payout metadata
(Natty Hatty does NOT store full card numbers or CVV.)
2.3 Signature & Legal Document Data
Signed waivers
Signing audit trails (IP, device ID, hash)
Contract metadata
Document storage paths
2.4 Authentication Data
Passwords (hashed + salted)
MFA tokens
Session identifiers
Device fingerprints
2.5 System Secrets & Keys
AWS credentials
API keys
Encryption keys
Internal tokens
2.6 Safety & Incident Data
Reports involving minors
Abuse or misconduct flags
Law enforcement escalation data
Required Controls
AES-256 encryption at rest
TLS 1.2+ in transit
Strict role-based access control
Multi-factor authentication
Zero sharing outside need-to-know
Logging and monitoring
No AI or ML model ingestion
No export without encryption
Must never be stored on employee personal devices
3. Tier 2 — Confidential Data
High sensitivity — protected but less regulated than Tier 1.
Confidential Data includes information that affects security, operations, or business viability but does not directly endanger minors.
Examples
Organization administrator information
Coach accounts (adult data)
Program pricing and configurations
Payment settings (non-sensitive)
Internal dashboards
Analytics and usage data
Performance logs without identifiers
Support tickets
Marketing contact lists
Access and event logs
Internal API documentation
Required Controls
Encryption at rest and in transit
Role-based access
Stored only on approved systems
Not shareable outside Natty Hatty or contracted org
No personal device storage
Optional MFA for partner access
4. Tier 3 — Internal Data
Internal-use information not harmful if disclosed in limited form.
This category includes general business operations data.
Examples
Company policies
Product roadmaps
Operational documentation
Development notes
Internal-only feature specs
Slack messages (non-sensitive)
HR non-confidential notices
Required Controls
Access limited to Natty Hatty staff
Internal distribution only
No external publication
Can be stored on secure employee devices
5. Tier 4 — Public Data
Safe for public release.
Data approved for public visibility.
Examples
Marketing website content
Legal policies (ToS, Privacy Policy, etc.)
Public API documentation
Help Center articles
Press statements
Public roadmap (if applicable)
Required Controls
No special restrictions
Must be approved by authorized personnel before publishing
6. Data Handling Requirements Per Tier
Activity | Restricted | Confidential | Internal | Public |
Encryption at Rest | Required | Required | Recommended | Optional |
Encryption in Transit | Required | Required | Recommended | Recommended |
RBAC Access | Strict | Controlled | Moderate | None |
MFA | Mandatory | Strongly recommended | Optional | Not required |
Cloud Storage | Approved only | Approved only | Allowed | Allowed |
Email Transmission | Prohibited unless encrypted | Allowed with caution | Allowed | Allowed |
Backup Retention | Mandatory with rotation | Mandatory | Recommended | Optional |
AI/ML Processing | Not allowed | Not allowed | Allowed with review | Allowed |
Export / Download | Highly restricted | Controlled | Allowed | Allowed |
Deletion Requests | Follows COPPA/CPRA + legal retention | Per policy | Standard | N/A |
7. Third-Party and Vendor Handling
Natty Hatty uses Stripe, AWS, and other sub-processors. Vendors must:
Meet Tier 1 data protection standards for payment and minors data
Provide SOC 2 or equivalent assurances
Sign Data Processing Agreements (DPAs)
Use encryption in transit and at rest
Meet contract-based retention and deletion requirements
Natty Hatty must approve any vendor with access to Restricted or Confidential data.
8. Retention Rules by Data Type
Aligns with your other signed policies.
Tier 1
Legal documents / waivers → Permanent or org-defined
Payments → 5–7 years (Stripe rules)
Safety records → As required by law
Minor personal data → Until program completion + retention window
Tier 2
Admin data → Duration of account
Logs → 30–180 days depending on type
Analytics → Aggregated & anonymized
Tier 3
Internal docs → Until superseded
Tier 4
Public content → As long as published
9. Data Transmission Restrictions
Restricted Data may NOT be sent through:
Unencrypted email
SMS or WhatsApp
External messaging apps
Non-Natty Hatty systems
Insecure file uploads
AI/ML training systems
Personal employee devices
Allowed Transmission Channels
Natty Hatty infrastructure
Encrypted AWS services
Encrypted backups
Encrypted emails using approved methods (if absolutely necessary)
10. Enforcement & Violations
Violations of this policy may result in:
Account suspension
Access removal
Termination of contractor agreements
Legal reporting when minors’ data is at risk
Organization account termination
Natty Hatty will always prioritize child safety in enforcement actions.
11. Contact
For questions, security review, or classification issues: