Privacy Notice

1. Who is responsible for your information

HID Global Corporation is the data controller. It decides why and how your information is used.

This tool is built and operated on HID's behalf by Right on the Line Limited, which acts as a processor (an "operator" under South African law). Right on the Line only uses your information to run this tool on HID's documented instructions. Your data passes through Right on the Line's systems and those of its suppliers, which is why they are named here rather than hidden behind the brand.

You can raise a privacy question with either HID or Right on the Line. You do not have to work out which one to ask.

2. What we collect

Your assessment answers

The nine questions in the assessment ask about how your organisation manages building access:

These answers describe your organisation's security posture rather than your personal life. We treat them as sensitive anyway: read together they say something meaningful about your buildings and your safeguarding arrangements. They are stored against your name and email when you ask for your results.

Your contact details

Only when you choose to receive your results, and only these four fields: your name, your role, your church or organisation name, and your work email address.

Your cookie choices

Which cookie categories you accepted, when, which version of our notices was in force, and whether your browser sent a Global Privacy Control signal. See the Cookie Notice.

How we measure the tool itself

We count how the assessment is used — how many people arrive, how far they get, which questions they answer, and which question they give up on. We do this for everyone, not only for people who accept optional cookies, because otherwise the numbers would describe a self-selecting minority and tell us nothing useful about where the tool is confusing.

It works like this, and the detail matters more than the summary:

We rely on legitimate interests for this, and the reasoning is in section 3. If you would rather we did not, see Your rights — you can object, and the Global Privacy Control signal above does the same job immediately.

What we deliberately do not collect

This tool does not fingerprint your device, does not build a lasting profile of you, does not record your precise location, and does not track you across other websites. We do not join your browsing to your name or email address unless you complete the form, and even then only to link your own submission to the visit that produced it. If you accept optional cookies, the third parties named below may do some of these things; if you do not, none of it happens.

3. Why we use it, and our legal basis

Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them. You can ask us for that assessment, and you can object — see Your rights.

Receiving your results does not depend on agreeing to marketing. The marketing box is unticked by default and leaving it unticked changes nothing about the results you get.

4. How we use AI

Your written results are drafted by an AI model (OpenAI's GPT-4o mini) so that they respond to your specific answers rather than reading as a generic template.

Your name, email address, role and organisation name are deliberately excluded from that request. The model receives your answers and the recommended solution tier, and nothing that identifies you or your organisation. OpenAI does not use data submitted through its API to train its models.

The scoring itself is a fixed calculation, not an AI judgement, and there is a written fallback if the AI step fails. No decision is made about you that produces a legal or similarly significant effect, so the automated decision-making rules in Article 22 of the GDPR do not apply. AI-generated text can still be wrong — please read the Terms of Use on that point.

5. Who we share it with

Measuring the tool adds nobody to this list. The country lookup described in section 2 runs against a database file on our own server rather than by asking an outside service, so no third party receives your IP address, and the figures we produce are never shared with an advertising provider.

Each of these is contractually bound to use your information only for the purpose above. We do not sell your information. We may also disclose information where the law requires it, or to establish or defend legal claims.

Google and LinkedIn receive nothing at all unless you opt in. We do not even load Google Tag Manager, which is what delivers those tags, until you have accepted at least one optional cookie category — so no request reaches Google or LinkedIn, and neither learns your IP address, before you have made a choice. If you later turn a category off, we delete the cookies we can reach and reload the page so nothing further is sent.

Note that LinkedIn and Google decide for themselves how they use the information collected through their own tags, so for that activity they act as controllers in their own right rather than purely on our instructions. Their own privacy policies apply: Google and LinkedIn.

6. Where your information goes

Every supplier above is hosted in the United States, so your information will be transferred outside the UK, the EEA and South Africa.

You can ask us for a copy of the relevant safeguards using the contact details below.

7. How long we keep it

Your submission is automatically deleted 24 months after you complete the assessment. This is enforced by the database itself, not by anyone remembering to do it. After that, your results link stops working.

Measurement records are deleted after 180 days, again by the database itself. These are the records described in section 2: they contain a country, a browser description, which questions were answered and how far the visit got. They contain no name, no email address and no IP address, and after the daily key is destroyed they cannot be connected to a person at all.

We keep daily totals — how many visits there were on a given day, how many reached each step — indefinitely, because they are counts with nothing identifying in them and losing them would mean losing any sense of whether the tool is improving.

Two things outlive that deletion, and you should know about them:

9. Your rights

Under UK and EU data protection law you can ask us to:

Where we rely on your consent, you can withdraw it at any time. Withdrawing consent does not affect anything we did before you withdrew it.

To object to being measured, turn on Global Privacy Control in your browser. We check for that signal on every request and record nothing when it is present, so it takes effect immediately and needs no email from you. Emailing us works too; the signal is simply faster.

Under POPIA you have equivalent rights, including access (section 23), correction or deletion (section 24), objection (section 11(3)) and the right to stop direct marketing (section 69(3)(c)). You may also make a request under the Promotion of Access to Information Act.

To exercise any of these, email brad@rightontheline.com for anything about this tool, or privacy@hidglobal.com with "SAR" in the subject line for anything about HID's wider records. We respond within one month (45 days for requests under California law, extendable once where the request is complex). We may need to verify your identity first, and we will not charge you.

If you are unhappy with how we have handled things, please tell us first so we can put it right. You can also complain to a regulator:

10. Notice for California residents

In the past 12 months this tool has collected the following categories of personal information under the CCPA/CPRA: identifiers (name, email address), professional information (job role, organisation), and internet activity (how the assessment was used, plus a country derived from your IP address — see section 2). Some internet activity is collected for every visitor, not only those who accept optional cookies, and we would rather say so plainly than let the earlier wording stand. It does not collect biometric information, precise geolocation, sensitive personal information, or information about protected characteristics.

Our own measurement is neither a sale nor a share. It stays on our systems, no advertising provider receives any part of it, and it builds nothing that could be used to target you elsewhere. What follows is about the advertising cookies, which are a separate matter.

We do not sell your personal information. We do, however, "share" it in the specific sense the CPRA uses: if you accept Marketing cookies, we use Google Display Network and LinkedIn remarketing, which discloses your identifiers to those providers for cross-context behavioural advertising. We are naming that plainly rather than relying on the word "may".

Three things follow from it, and all three are already in place:

We honour Global Privacy Control. If your browser sends a GPC signal we treat it as a valid opt-out of sale and sharing, and Performance and Marketing cookies are switched off automatically without you having to do anything. We also stop measuring the visit entirely, which the signal does not oblige us to do — we do it because a signal that says "do not track me" is clear enough about what is wanted.

You have the right to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information (we collect none), and not to be discriminated against for exercising any of these rights. Use the contact details in section 14.

11. Children

This tool is intended for adults responsible for facilities, operations, IT or security at their organisation. It is not directed at children and we do not knowingly collect information from anyone under 18. Some questions ask about access to children's ministry areas, but they ask about your systems — we never ask for, and you should never enter, any information about a child. If you believe a child has submitted information, contact us and we will delete it.

12. Security

Traffic is encrypted in transit. Access to the database is restricted to named administrators. Contact details are removed from our application logs before they are written. Your email address is never sent to the browser by the results page. We keep the number of suppliers who see your data to the minimum needed to deliver the service.

13. Changes to this notice

The version number and date at the top of this page change whenever we update it. If we make a material change to how we use your information or to our cookie categories, we will ask you for your cookie choices again rather than assuming the old answer still stands.

14. How to contact us