Back
Security
Natty Hatty — Audit Trail Policy (Website)
Last Updated: November 15, 2025
Version: v1.0
Natty Hatty, Inc. (“Natty Hatty,” “we,” “our,” “us”) provides digital tools that allow organizations (“Organizations”) to collect legally binding electronic signatures and participant information through Natty Hatty–hosted public pages, including:
Public signature pages
Public registration and checkout flows
QR-code–accessed signature pages
Payment + signature combined flows
This Audit Trail Policy explains how Natty Hatty generates, stores, and secures audit trails associated with all signatures, including those executed on behalf of minors.
1. Purpose of Audit Trails
Audit trails allow Natty Hatty to:
Validate electronic signatures
Confirm parent or guardian consent for minors
Maintain legal compliance (ESIGN, UETA, eIDAS)
Provide verifiable evidence for Organizations
Support safety and insurance requirements
Preserve document integrity
Detect fraud or unauthorized activity
Natty Hatty does not use audit trail data for advertising or AI/ML training.
2. What Natty Hatty Records in an Audit Trail
For every signature (adult, parent/guardian, or minor), Natty Hatty captures:
2.1 Signer Identification Data
Name as entered
Relationship to minor (when applicable)
Email address (if provided)
Phone number (if used for verification)
2.2 Minor Participant Details (When Applicable)
If a document involves a minor:
Minor’s name
Minor’s date of birth (if included in the form)
Name and identity of the parent or legal guardian signing on the minor’s behalf
Confirmation that the signer attests to legal authority over the minor
Natty Hatty does not collect minor contact information unless required by the Organization.
2.3 Technical Metadata
IP address
Device type
Browser and operating system
Approximate time zone
2.4 Signature Event Data
Exact timestamp of signature
Signature method (typed, drawn, checkbox, multi-step)
Explicit consent to use electronic signatures
Minor signature status (parent signing on behalf of minor vs. minor signing where permitted by the Organization)
Payment event linkage (if combined with checkout)
Natty Hatty allows minors to sign only if the Organization configures a document specifically requiring a minor’s acknowledgment (e.g., code of conduct).
Minors cannot legally sign liability waivers; a parent or guardian signature is always required. This responsibility belongs to the Organization.
2.5 Document Data
Document version ID
Cryptographic hash (tamper-proof fingerprint)
Organization that issued the document
Signature ID
2.6 Integrity & Security Data
Audit log hash
Event chain confirmations
Document locking status
3. Audit Trail Creation & Sealing
After a document is signed (by a parent or guardian, or by a minor where applicable):
A permanent audit log is created
The signed document is cryptographically hashed
The document is locked against modification
All associated minor and guardian information is bound to the audit trail
The entire signature event becomes immutable
Audit trails cannot be edited, rewritten, or selectively removed.
4. Audit Trail Retention
Audit trails for both adults and minors are retained for the same duration as the associated signed documents.
Typical retention:
Up to 7 years, or as required by the Organization.
However, for minors:
Certain youth-safety regulations may require extended retention (e.g., until the minor reaches age 18 plus any statutory period)
Natty Hatty will retain such documents until the Organization instructs otherwise, if legally permitted
Signed minor-related documents cannot be deleted due to a refund or program cancellation.
5. Audit Trails for Minor Signatures & Guardian Consent
When a minor is involved, Natty Hatty records:
Identity of the parent or guardian signing on behalf of the minor
Confirmation that the signer declares legal authority
Any minor acknowledgment (if configured by the Organization)
Acceptance of relevant policies, codes of conduct, or participation rules
A full chain-of-custody log connecting the minor to the guardian’s signature
Natty Hatty does not verify parent or guardian identity or legal authority; this responsibility belongs to the Organization.
6. Document Integrity & Non-Repudiation
Natty Hatty ensures that:
Guardians cannot deny having signed
Minor acknowledgments (where applicable) cannot be altered
Signed documents cannot be modified
Hash verification protects against tampering
All versions remain traceable
Signatures remain valid even after refunds or program changes
7. Access to Audit Trails
Organizations
may access audit logs for all signatures, including those involving minors.
Organizations can use logs for:
Legal evidence
Insurance claims
Compliance
Safety investigations
Program administration
Parents / Guardians
may obtain copies of signed documents by contacting the Organization.
Natty Hatty cannot provide documents directly unless required by law.
Natty Hatty Staff
may access audit trails only for:
Support
Fraud detection
Legal compliance
System reliability
Security investigations
Natty Hatty staff cannot modify or delete audit logs.
8. Youth-Specific Legal Compliance
Audit trails involving minors support compliance with:
COPPA (Children’s Online Privacy Protection Act)
State youth safety and liability requirements
ESIGN and UETA parent or guardian consent standards
Insurance documentation requirements
Sports-governing-body requirements
Natty Hatty does not collect unnecessary minor data and does not sell or share minor information.
9. Fraud Prevention & Abuse Detection
Audit trails may be used to detect:
Unauthorized guardian signatures
Payment misuse
Duplicate or conflicting signature submissions
Device or identity anomalies
Attempts to bypass parental authority safeguards
Natty Hatty may restrict access if audit logs indicate abuse or fraud.
10. No Alteration of Audit Information
Audit trails:
Cannot be edited
Cannot be partially deleted
Cannot be overridden by Organizations or users
Can only be removed under lawful retention deletion rules
11. Contact Information
For audit trail questions:
For copies of your signed documents:
Contact the Organization that created the document.