Privacy Notice
This notice covers this assessment tool only. HID Global's general Privacy Notice describes how HID handles personal information across its business, and it continues to apply. This notice adds the detail specific to this tool: what it asks you, where those answers go, and who operates it. Where the two differ about this tool, this notice is the accurate one.
1. Who is responsible for your information
HID Global Corporation is the data controller. It decides why and how your information is used.
- HID Global Corporation, 611 Center Ridge Drive, Austin, TX 78753, United States
- privacy@hidglobal.com
This tool is built and operated on HID's behalf by Right on the Line Limited, which acts as a processor (an "operator" under South African law). Right on the Line only uses your information to run this tool on HID's documented instructions. Your data passes through Right on the Line's systems and those of its suppliers, which is why they are named here rather than hidden behind the brand.
- Right on the Line Limited, registered in England and Wales, company no. 04044730
The Regent, Chapel Street, Penzance, Cornwall, TR18 4AE, United Kingdom - Marketing Contract Services (Pty) Ltd (South Africa)
21 Casten Drive, Groenvlei, Bloemfontein, 9301, South Africa - Privacy contact and POPIA Information Officer: brad@rightontheline.com, +44 (0)1256 882288
You can raise a privacy question with either HID or Right on the Line. You do not have to work out which one to ask.
2. What we collect
Your assessment answers
The nine questions in the assessment ask about how your organisation manages building access:
- How you issue credentials, and how quickly you remove access when someone leaves
- How many buildings or campuses you run, and roughly how many people hold access
- Whether you use tiered access zones, and who owns access decisions
- Whether you can see who has access to children's ministry areas
- Whether you experience seasonal access spikes
- Whether you have had a security incident or needed to re-key
These answers describe your organisation's security posture rather than your personal life. We treat them as sensitive anyway: read together they say something meaningful about your buildings and your safeguarding arrangements. They are stored against your name and email when you ask for your results.
Your contact details
Only when you choose to receive your results, and only these four fields: your name, your role, your church or organisation name, and your work email address.
Your cookie choices
Which cookie categories you accepted, when, which version of our notices was in force, and whether your browser sent a Global Privacy Control signal. See the Cookie Notice.
How we measure the tool itself
We count how the assessment is used — how many people arrive, how far they get, which questions they answer, and which question they give up on. We do this for everyone, not only for people who accept optional cookies, because otherwise the numbers would describe a self-selecting minority and tell us nothing useful about where the tool is confusing.
It works like this, and the detail matters more than the summary:
- When your browser sends us something to record, we use your IP address and browser description to work out which country you are in and to calculate a scrambled identifier that lets us tell one visit apart from another.
- Your IP address is never written down. It is used to calculate those two things and then discarded in the same moment. It is not stored in our database, not written to our server logs, and not sent anywhere.
- The scrambling key changes every day and is destroyed two days later. Once that has happened, yesterday's identifier cannot be linked to today's, or worked back to you — not by anyone, including us. It is not a lasting identifier and it cannot follow you.
- Country lookup uses a database stored on our own server. No other company is involved and nobody else sees your IP address.
- Nothing is stored on your device. No cookie, no local storage, nothing. That is why this does not appear in the cookie banner: there is nothing on your device to ask your permission about. The Cookie Notice explains that distinction in full.
- If your browser sends a Global Privacy Control signal, we record nothing at all. That is more than the law requires and it is the simplest way to opt out.
We rely on legitimate interests for this, and the reasoning is in section 3. If you would rather we did not, see Your rights — you can object, and the Global Privacy Control signal above does the same job immediately.
What we deliberately do not collect
This tool does not fingerprint your device, does not build a lasting profile of you, does not record your precise location, and does not track you across other websites. We do not join your browsing to your name or email address unless you complete the form, and even then only to link your own submission to the visit that produced it. If you accept optional cookies, the third parties named below may do some of these things; if you do not, none of it happens.
3. Why we use it, and our legal basis
| What we do | Legal basis (UK/EU GDPR) | Legal basis (POPIA) |
|---|---|---|
| Score your answers, generate your results page and email you the link | Article 6(1)(b) — steps taken at your request | Section 11(1)(b) |
| Compare your scores against an anonymous peer average | Article 6(1)(f) — legitimate interests. Only aggregate counts are stored; no individual organisation is identifiable | Section 11(1)(f) |
| Measure how the assessment is used, so we can see where it confuses people and fix it | Article 6(1)(f) — legitimate interests. No information is stored on your device, so the cookie rules (PECR regulation 6) are not engaged. Your IP address is used to derive a country and a daily-changing identifier and is then discarded | Section 11(1)(f) |
| Pass your details to HID so it can follow up about this assessment | Article 6(1)(f) — legitimate interests in responding to a business enquiry you initiated | Section 11(1)(f) |
| Send you further marketing about HID products and events | Article 6(1)(a) — your consent, given by ticking the optional box | Section 69 — your consent |
| Stop any existing outreach campaign now that you have been in touch | Article 6(1)(f) — legitimate interests; the effect is that you receive fewer messages, not more | Section 11(1)(f) |
| Set optional cookies | Article 6(1)(a) — your consent, plus PECR regulation 6 | Section 11(1)(a) |
| Keep our systems secure and meet our legal obligations | Articles 6(1)(c) and 6(1)(f) | Sections 11(1)(c) and 11(1)(f) |
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them. You can ask us for that assessment, and you can object — see Your rights.
Receiving your results does not depend on agreeing to marketing. The marketing box is unticked by default and leaving it unticked changes nothing about the results you get.
4. How we use AI
Your written results are drafted by an AI model (OpenAI's GPT-4o mini) so that they respond to your specific answers rather than reading as a generic template.
Your name, email address, role and organisation name are deliberately excluded from that request. The model receives your answers and the recommended solution tier, and nothing that identifies you or your organisation. OpenAI does not use data submitted through its API to train its models.
The scoring itself is a fixed calculation, not an AI judgement, and there is a written fallback if the AI step fails. No decision is made about you that produces a legal or similarly significant effect, so the automated decision-making rules in Article 22 of the GDPR do not apply. AI-generated text can still be wrong — please read the Terms of Use on that point.
5. Who we share it with
| Who | What they receive | Why | Where |
|---|---|---|---|
| MongoDB Atlas | Your full submission, including contact details | Stores your results so your link keeps working | United States (Oregon) |
| Render | Hosts the application | Runs the website itself | United States (Oregon) |
| OpenAI | Your answers only — no identifiers | Drafts your written results | United States |
| MailerSend | Your name, email address and results link | Sends your results email | United States / EU |
| HubSpot | Your name, email, role, organisation, score and consent record | HID's customer relationship system, so HID can follow up | United States |
| Lemlist | Your email address only | Checks whether you are in an existing outreach campaign and pauses it | United States / EU |
| Google (Tag Manager, Analytics, Display Network) |
Only if you accept Performance or Marketing cookies: your IP address, browser and device details, and the pages you view. Never your name, email address, organisation or answers | Measures how the assessment is used, which campaigns bring people to it, and — if you accept Marketing — shows you HID adverts on other websites | United States |
| Only if you accept Marketing cookies: your IP address, browser details, and the fact that you visited | Measures which LinkedIn campaigns led to a completed assessment, and shows you HID adverts on LinkedIn | United States |
Measuring the tool adds nobody to this list. The country lookup described in section 2 runs against a database file on our own server rather than by asking an outside service, so no third party receives your IP address, and the figures we produce are never shared with an advertising provider.
Each of these is contractually bound to use your information only for the purpose above. We do not sell your information. We may also disclose information where the law requires it, or to establish or defend legal claims.
Google and LinkedIn receive nothing at all unless you opt in. We do not even load Google Tag Manager, which is what delivers those tags, until you have accepted at least one optional cookie category — so no request reaches Google or LinkedIn, and neither learns your IP address, before you have made a choice. If you later turn a category off, we delete the cookies we can reach and reload the page so nothing further is sent.
Note that LinkedIn and Google decide for themselves how they use the information collected through their own tags, so for that activity they act as controllers in their own right rather than purely on our instructions. Their own privacy policies apply: Google and LinkedIn.
6. Where your information goes
Every supplier above is hosted in the United States, so your information will be transferred outside the UK, the EEA and South Africa.
- UK and EU: transfers are covered by the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, or by HID's certification under the EU–US and Swiss–US Data Privacy Frameworks. We have assessed the risk of these transfers and applied additional safeguards where needed.
- South Africa: transfers are made under section 72 of POPIA, on the basis of binding contractual terms requiring a comparable level of protection.
You can ask us for a copy of the relevant safeguards using the contact details below.
7. How long we keep it
Your submission is automatically deleted 24 months after you complete the assessment. This is enforced by the database itself, not by anyone remembering to do it. After that, your results link stops working.
Measurement records are deleted after 180 days, again by the database itself. These are the records described in section 2: they contain a country, a browser description, which questions were answered and how far the visit got. They contain no name, no email address and no IP address, and after the daily key is destroyed they cannot be connected to a person at all.
We keep daily totals — how many visits there were on a given day, how many reached each step — indefinitely, because they are counts with nothing identifying in them and losing them would mean losing any sense of whether the tool is improving.
Two things outlive that deletion, and you should know about them:
- The anonymous peer benchmark keeps running totals only. Nothing in it can be traced back to you or your organisation, so it is not deleted.
- Your contact record in HID's HubSpot system is held under HID's own retention schedule, as described in HID's Privacy Notice. Deleting our copy does not delete HID's, so if you want everything removed, say so and we will pass the request on.
8. Your results link
Your results page has a long, randomly generated web address that is not listed or indexed by search engines. Anyone who has that address can open the page and will see your first name, your organisation name and your answers. Your email address is never shown on that page and is never sent to your browser.
The link is designed to be shared with your leadership team. Please treat it as you would any other shared document, and do not treat it as a secure or access-controlled record.
9. Your rights
Under UK and EU data protection law you can ask us to:
- give you a copy of the information we hold about you
- correct anything that is wrong or incomplete
- delete your information
- restrict how we use it, or object to us using it — including any use based on legitimate interests
- provide it in a portable, machine-readable format
- stop sending you marketing, at any time and without giving a reason
Where we rely on your consent, you can withdraw it at any time. Withdrawing consent does not affect anything we did before you withdrew it.
To object to being measured, turn on Global Privacy Control in your browser. We check for that signal on every request and record nothing when it is present, so it takes effect immediately and needs no email from you. Emailing us works too; the signal is simply faster.
Under POPIA you have equivalent rights, including access (section 23), correction or deletion (section 24), objection (section 11(3)) and the right to stop direct marketing (section 69(3)(c)). You may also make a request under the Promotion of Access to Information Act.
To exercise any of these, email brad@rightontheline.com for anything about this tool, or privacy@hidglobal.com with "SAR" in the subject line for anything about HID's wider records. We respond within one month (45 days for requests under California law, extendable once where the request is complex). We may need to verify your identity first, and we will not charge you.
If you are unhappy with how we have handled things, please tell us first so we can put it right. You can also complain to a regulator:
- UK: Information Commissioner's Office, ico.org.uk, 0303 123 1113
- EU: the supervisory authority in your country of residence
- South Africa: Information Regulator, inforegulator.org.za
10. Notice for California residents
In the past 12 months this tool has collected the following categories of personal information under the CCPA/CPRA: identifiers (name, email address), professional information (job role, organisation), and internet activity (how the assessment was used, plus a country derived from your IP address — see section 2). Some internet activity is collected for every visitor, not only those who accept optional cookies, and we would rather say so plainly than let the earlier wording stand. It does not collect biometric information, precise geolocation, sensitive personal information, or information about protected characteristics.
Our own measurement is neither a sale nor a share. It stays on our systems, no advertising provider receives any part of it, and it builds nothing that could be used to target you elsewhere. What follows is about the advertising cookies, which are a separate matter.
We do not sell your personal information. We do, however, "share" it in the specific sense the CPRA uses: if you accept Marketing cookies, we use Google Display Network and LinkedIn remarketing, which discloses your identifiers to those providers for cross-context behavioural advertising. We are naming that plainly rather than relying on the word "may".
Three things follow from it, and all three are already in place:
- Nothing in that category loads until you opt in. We do not even request Google Tag Manager, which delivers those tags, before you have chosen.
- You can turn it off at any time through Cookie Settings, which is your right to opt out of sharing.
- Advertising providers never receive your name, email address, organisation or your assessment answers. They receive the fact of the visit and standard browser information.
We honour Global Privacy Control. If your browser sends a GPC signal we treat it as a valid opt-out of sale and sharing, and Performance and Marketing cookies are switched off automatically without you having to do anything. We also stop measuring the visit entirely, which the signal does not oblige us to do — we do it because a signal that says "do not track me" is clear enough about what is wanted.
You have the right to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information (we collect none), and not to be discriminated against for exercising any of these rights. Use the contact details in section 14.
11. Children
This tool is intended for adults responsible for facilities, operations, IT or security at their organisation. It is not directed at children and we do not knowingly collect information from anyone under 18. Some questions ask about access to children's ministry areas, but they ask about your systems — we never ask for, and you should never enter, any information about a child. If you believe a child has submitted information, contact us and we will delete it.
12. Security
Traffic is encrypted in transit. Access to the database is restricted to named administrators. Contact details are removed from our application logs before they are written. Your email address is never sent to the browser by the results page. We keep the number of suppliers who see your data to the minimum needed to deliver the service.
13. Changes to this notice
The version number and date at the top of this page change whenever we update it. If we make a material change to how we use your information or to our cookie categories, we will ask you for your cookie choices again rather than assuming the old answer still stands.
14. How to contact us
- About this tool: Right on the Line Limited, brad@rightontheline.com, +44 (0)1256 882288, The Regent, Chapel Street, Penzance, Cornwall, TR18 4AE, United Kingdom
- POPIA Information Officer: as above, at Marketing Contract Services (Pty) Ltd, 21 Casten Drive, Groenvlei, Bloemfontein, 9301, South Africa
- HID Global: privacy@hidglobal.com, HID Global Corporation, 611 Center Ridge Drive, Austin, TX 78753, United States