Rotary District 9510
REVIEW EDITION
F11 configured supporting document

QR Contact Form Setup Guide

A controlled, editable working derivative for M-T1-CP-04-SD-03. Complete local facts, approvals and operational evidence before use.

Release truth. This file is configured for substantive review. It is not approved for public distribution or operational use. Local law, insurance, safeguarding, accessibility, privacy, brand, rights and accountable-owner checks remain mandatory.

M-T1-CP-04-SD-03 — QR Contact Form Setup Guide

Release control

FieldControlled value
StatusREVIEW — configured derivative; privacy, communications, security, accessibility, service and production approval required before publication
Supporting-document codeM-T1-CP-04-SD-03
Exact derivative titleQR Contact Form Setup Guide
Source initiativeM-T1-CP-04 - Pop-Up Rotary Displays
Source initiative codeM-T1-CP-04
Source initiative titlePop-Up Rotary Displays
Initiative dispositionCanonical retained
Canonical parentM-T1-CP-04 - Pop-Up Rotary Displays
Canonical parent code and titleM-T1-CP-04 - Pop-Up Rotary Displays
Named overlay or migration labelCanonical static-display body
Redirect or tombstone routeNone
Family masterPlaybook_F11_Digital_QR_Data_Capture_Master.md
Family / master versionF11 / 1.0
Recorded master SHA-256e9f831e4adda1cd5f17f244cea7bfc694b3c1ce6562f5c0272db613a4f2eba29
Authoritative indexPlaybook_Supporting_Documents_Master_Index.md v1.1
Configured master variantF11 controlled Playbook asset — single mapped Pop-Up Rotary Displays derivative
Derivative versionv0.1

Adaptation note

This derivative configures the canonical static-display QR journey for Pop-Up Rotary Displays. It connects one clear public action to a minimal, accessible form; separates requested operational contact from optional future updates; uses an organisation-controlled HTTPS destination and visible short route; records privacy, security, routing, retention and decommissioning controls; engineers the QR from the final payload; and requires production-equivalent device, accessibility, network, print and follow-up testing before launch.

Privacy, communications and legal boundary. This is operational guidance, not legal advice. The host entity must obtain current review appropriate to its legal status, activity, audience, platforms and jurisdictions. Do not assume an exemption from Australian privacy, electronic-message or other obligations. Record the local determination and conditions.

1. Instructions and non-negotiable release rule

  1. Declare one primary purpose and public action. Remove collection where public information can meet the need.
  2. Record a necessity, access role, required/optional decision and retention link for every field before opening the form builder.
  3. Resolve the host, data owner, privacy/communications/security/accessibility reviewers, follow-up owner, incident lead and approver.
  4. Configure the form, notice, choices, routing, preferences, security, retention and safe closed state in a production-equivalent environment.
  5. Freeze and peer-check the exact destination and attribution values before generating the QR.
  6. Produce a vector QR master, accessible lock-up, visible typed route and actual-size physical proof.
  7. Execute every applicable digital, routing, accessibility, network, device and print test and retain evidence for the exact version.
  8. Sign all approval gates, conduct a live installed scan, monitor the service and decommission safely.

If a required owner, gate, test or evidence item is absent, the public QR does not ship. A scan that opens a page is not proof that the complete service works.

2. Controlled configuration fields

Identity, approval and ownership

Controlled fieldResolved valueSource / evidenceOwnerVerified date
Local derivative / form name________________________________________________________________
Host entity and public contact________________________________________________________________
Data Owner / Form Owner________________________________________________________________
System Administrator________________________________________________________________
Privacy / Communications Reviewers________________________________________________________________
Security / Accessibility Reviewers________________________________________________________________
Follow-up Owner / cover________________________________________________________________
Incident Lead________________________________________________________________
Final Approver________________________________________________________________
Immutable version / approval date________________________________________________________________
Next review / decommission date________________________________________________________________

Purpose, audience and choices

Controlled fieldResolved value
Primary purpose — one plain-language outcome______________________________
Primary display action______________________________
Intended audience / separately handled groups______________________________
Public-information alternative______________________________
Explicit sensitive-data exclusions______________________________
Under-18 / welfare / safeguarding route______________________________
Collection notice version______________________________
Privacy-policy route______________________________
Operational response choice______________________________
Separate optional future-updates choice______________________________
Choice wording version / timestamp / source______________________________
Preference / withdrawal / suppression routes______________________________

Destination, QR, service and lifecycle

Controlled fieldResolved value
Canonical HTTPS URL______________________________
Visible human-readable short URL______________________________
Exact QR payload______________________________
QR filename / version______________________________
Finished size / module / quiet zone______________________________
Foreground/background / contrast result______________________________
Error correction and reason______________________________
Print context / substrate / finish / lighting______________________________
Intended and tested scan distance______________________________
Redirect owner / peer-approval / expiry______________________________
Attribution source / medium / campaign / content______________________________
Internal display source code______________________________
Follow-up queue / owner / service level / escalation______________________________
Platform / vendor / data location______________________________
Access roles / MFA / logging / export route______________________________
Retention trigger / period / deletion route______________________________
Incident route______________________________
Analytics purpose / bot-test filter / reporting cadence______________________________
Safe closed-page URL / archive route______________________________

Never infer an owner, legal status, data location, response commitment or retention period.

3. Purpose and data-minimisation gate

Decision questionPass conditionLocal evidencePass
Can public information meet the need without collection?No form on that pathway, or collection justified__________________[ ]
Can the action be anonymous?Anonymous route offered where workable__________________[ ]
Is there exactly one declared primary purpose?Specific, current and visible__________________[ ]
Does every field directly support that purpose?One-sentence necessity for each__________________[ ]
Is each required field genuinely necessary?Operational reason and consequence documented__________________[ ]
Is a lower-risk data type sufficient?Lower-risk option selected__________________[ ]
Is speculative “useful later” collection absent?No open-ended future-use field__________________[ ]
Are free-text fields removed or tightly constrained?Purpose, include/exclude instruction, limit and restricted route__________________[ ]
Are higher-risk data excluded or separately approved?Identity, financial, credential, health, criminal and precise-location data excluded by default__________________[ ]

Stop rule: remove a field whose necessity cannot be stated in one clear sentence.

4. Form journey

Screen / sectionPurposeConfigured content
1. LandingConfirm host, purpose and right destinationHost identity, form name, action, time estimate, public-information option
2. InterestChoose a serviceable next stepShort controlled interest list
3. ContactCollect only the selected reply channelPreferred method and conditional email/phone/other field
4. ContextCapture essential routing detailConstrained values; approved limited text only
5. ChoicesSeparate requested reply from future updatesIndependent, unbundled choices
6. NoticeExplain collection before submissionHost, purpose, handling, consequence, policy and privacy contact
7. SubmitState the actual action“Request information” or other approved specific label
8. ConfirmationConfirm receipt and next step safelyService level, public resources, preference route; no submitted data echoed

5. Field specification

Field IDVisible persistent labelTypeRequired? / reasonData categoryHelp / include-excludeValidation / errorLogicAccessRetention link
F-01Area of interestControlled choiceRequired / routingPreferenceChoose one current optionSelect one option / Explain recoveryAlwaysFollow-up roles__________________
F-02Preferred contact methodControlled choiceRequired / replyContact preferenceChoose available routeSelect one / Explain recoveryAlwaysFollow-up roles__________________
F-03Email or phone for selected methodAppropriate inputRequired only for selected methodContact detailEnter only chosen reply detailFormat rule / Specific recoveryConditionalFollow-up roles__________________
F-04Essential contextControlled choice / limited textOptional or justifiedEnquiry contextState what not to includeCharacter limit / recoveryApproved onlyRestricted queue__________________
F-_____________________________________________________________________________________________________________________________________________________________________

Field rules:

6. Routing categories

Visitor needMinimum useful collectionRoute / ownerControl
Learn moreNonePublic informationPrefer no collection
Ask a questionContact method/detail and constrained topicGeneral enquiry queue: __________Limit open text
Attend a meetingContact method and meeting/location preferenceMeeting owner: __________No automatic future updates
Volunteer or join an activityContact method and opportunity categoryVolunteer owner: __________Apply safeguarding route
Invite a speakerContact, organisation and broad event windowSpeaker coordinator: __________Collect detailed logistics later
Explore partnershipContact, organisation and broad interestPartnership owner: __________Proposals outside public form
Accessibility supportPreferred contact and assistance routeAccessibility contact: __________Do not request diagnosis
Privacy/data requestDirect privacy contactPrivacy function: __________Do not route through marketing

Offer only categories the host can service.

7. Collection notice and independent choices

Reviewed notice structure

About this form
[Host entity] collects the information you choose to provide so we can [primary purpose]. If you do not provide a required item, [specific consequence]. Your response is sent to [owned route] and handled under our privacy information at [privacy-policy route]. For a privacy question or request, contact [host contact]. Any choice about future updates is optional and separate from the response you are requesting.

Add locally required disclosures about collection circumstances, usual or overseas disclosure, access/correction and complaint handling. Essential information stays in the form; a policy link does not carry the whole explanation.

Operational response

This governs the requested service response only.

Separate future updates

The future-updates choice is optional, unselected by default, versioned, timestamped and not a condition of the requested response.

Confirmation

Your request has been received. We aim to respond within [approved service level]. For public information, visit [route]. To change an optional future-updates choice, use [preference route].

Do not echo submitted contact details or private context.

8. Accessibility and equivalent fallback

Digital checks:

Fallback:

RouteNotice and choices preservedCustodySecure transcriptionOriginal disposal
Typed short URLSame digital journeyN/AN/AN/A
Assisted completionRead essential notice; preserve independent choicesAuthorised helperApproved systemNo informal notes
Paper formSame minimum fields/notice/choicesNamed custodianDual-checked routeApproved secure disposal
Telephone or email alternativeCollect only necessary informationNamed responderRestricted queueApproved route

Scanning is never the only way to act.

9. Canonical destination, redirect and attribution

Destination acceptance:

Short route acceptance:

Payload controlRelease value
Exact encoded payload______________________________
Canonical destination______________________________
Visible short route______________________________
Attribution sourcepop_up_display / approved value: __________
Mediumqr
Campaign______________________________
Content / placement variant______________________________
Internal display source______________________________
Redirect owner / expiry______________________________

Attribution values contain no name, email, phone, membership identifier, secret or sensitive location. Never repoint a printed QR to an unrelated purpose.

10. QR engineering and artwork specification

  1. Resolve and peer-check the exact payload.
  2. Open it directly in a private browser and confirm host, certificate, page and attribution.
  3. Generate a standards-conformant QR from that exact string.
  4. Record error correction based on payload density and production risk.
  5. Bind immutable master filename and QR version.
  6. Export vector for print and lossless high-resolution raster only where required.

Never generate, recreate, trace or upscale the QR with an image-generation tool.

AttributeConfigured production requirementEvidence
PayloadURL only; no personal data, secret or raw response__________________
Master formatSVG, PDF or EPS vector; crisp square modules__________________
Raster, if requiredLossless PNG at sufficient resolution for at least 300 ppi at placed size__________________
Starting hand-held sizeAt least 25 mm square before density/context adjustment; final proof controls__________________
Final size / module________________________________________________
Quiet zoneAt least four modules on every side__________________
Colour / contrastDark symbol on plain light background; recorded result__________________
DistortionNo stretch, skew, crop, rotation, warp or non-uniform scaling__________________
DecorationNo logo, icon, photo, gradient or texture inside the symbol unless separately engineered and exhaustively tested__________________
PlacementFlat, unobstructed, away from fold, trim, curve and glare__________________
LabelSpecific action plus visible typed short route__________________
Context / distanceActual substrate, finish, light and intended range__________________

If an official Rotary mark is placed adjacent to the QR, use only the supplied original asset, preserve its colours and proportions, account for transparent padding and keep it entirely outside the QR quiet zone. Do not generate, substitute or stretch a mark.

Print handoff includes the immutable vector master, exact size, locked aspect ratio, quiet-zone/no-crop/no-effects instructions, contrast/background, substrate/finish/light, proof approver and mandatory physical scan test. A screenshot of a QR is not a production master.

11. Device, network, accessibility and print test log

Test IDScenarioDevice / browser / network / print conditionExpectedActualResultEvidenceTester / date
QR-001Typed canonical, short, tagged and untagged routes__________________Correct host, notice and source__________________Pass / Fail____________________________________
QR-002Current supported iOS cameras__________________Detect and open correct route__________________Pass / Fail____________________________________
QR-003Current supported Android cameras__________________Detect and open correct route__________________Pass / Fail____________________________________
QR-004Private browser / no account__________________Complete without barrier__________________Pass / Fail____________________________________
QR-005Cellular, Wi-Fi and constrained network__________________Useful first content; no duplicate__________________Pass / Fail____________________________________
QR-006Offline / captive portal / service failure__________________Typed and assisted fallback visible__________________Pass / Fail____________________________________
QR-007Keyboard, focus, zoom and reflow__________________Full completion__________________Pass / Fail____________________________________
QR-008Screen reader, labels and errors__________________Correct name/role/state/recovery__________________Pass / Fail____________________________________
QR-009Required, malformed, maximum and corrected values__________________Specific recovery; one valid record__________________Pass / Fail____________________________________
QR-010Operational/future choices__________________Independent stored values/version__________________Pass / Fail____________________________________
QR-011Each interest route and service due date__________________Correct owner and alert__________________Pass / Fail____________________________________
QR-012Preference/withdrawal/suppression__________________End-to-end correct action__________________Pass / Fail____________________________________
QR-013Actual-size substrate proof__________________Reliable quiet zone/contrast scan__________________Pass / Fail____________________________________
QR-014Near/intended/far, angle and expected light/glare__________________Reliable in approved envelope__________________Pass / Fail____________________________________
QR-015Closed form and retired redirect__________________Safe closed page; no collection__________________Pass / Fail____________________________________

Blocker or high defects must close and affected regression tests repeat before release. An exception cannot waive privacy, security, destination, accessibility or response ownership.

12. Ownership and routing

Interest categoryDestinationNamed ownerService levelEscalationOut-of-office coverClosure definition
______________________________________________________________________________________________________________________________
______________________________________________________________________________________________________________________________

For every accepted submission: assign category, calculate due date, alert only the authorised route, acknowledge safely, record action/completion, keep future-update preference separate and escalate aged/sensitive cases. Never distribute raw responses to a club-wide list or use a publicly linked spreadsheet as the queue.

13. Platform, security, access and retention gate

ControlApproved value / evidenceReviewerPass
Platform/vendor/contract and data location____________________________________[ ]
Individual accounts and least privilege____________________________________[ ]
Multi-factor authentication____________________________________[ ]
Administrator, responder, export and audit roles____________________________________[ ]
Integration/webhook/API credential controls____________________________________[ ]
Logging, backup and recovery____________________________________[ ]
Approved logged export route____________________________________[ ]
Retention trigger and period by data category____________________________________[ ]
Deletion/de-identification and backup treatment____________________________________[ ]
Suppression/do-not-contact preservation____________________________________[ ]
Incident route and responder exercise____________________________________[ ]

Working exports are exceptional, logged, access-limited, time-bound and securely removed after approved transfer.

14. Incident response

  1. contain exposure or misrouting through authorised controls;
  2. preserve relevant logs, configuration, screenshots and version identifiers without uncontrolled copies;
  3. assess information, people, systems, access, consequences and ongoing risk;
  4. escalate to approved privacy, security, legal, records, communications and leadership routes;
  5. make notification decisions under current law and qualified advice;
  6. communicate verified facts and practical protective steps;
  7. validate destination, form, access, routing and preferences before reopening; and
  8. record cause, impact, decisions, actions, owners and prevention.
Incident referenceDate/timeImmediate containmentVersion / systemEscalated toReopen authorityRestricted evidence
______________________________________________________________________________________________________________________________

15. Analytics and service reporting

MeasureFormula / sourceDenominator and exclusionsInterpretation
QR landing sessionsEligible governed-source sessions after bot/test filter__________________A session is not necessarily a person
Form startsFirst meaningful form interaction__________________Define test exclusions
Completed submissionsAccepted non-test submissions__________________Remove duplicates by documented rule
Completion rateCompleted ÷ eligible starts__________________Journey measure, not impact
Future-updates selectionAffirmative valid choices ÷ eligible submissions shown choice__________________Not a quality score
Follow-up within service levelTimely actions ÷ eligible routed responses__________________Define pauses/exclusions
Next-step conversionDefined next step ÷ eligible responses__________________State observation window
Error / fallback useDefined errors or assisted/paper uses__________________Do not infer disability or preference

Small-number reporting must prevent re-identification. Scans and submissions are not community impact.

16. Change control and decommissioning

VersionChange / reasonRisk and reviewsRegression testsApprover / dateSupersedes
____________________________________________________________________________________________________________

Material changes to purpose, audience, field, notice, choice, platform, URL/payload, access, retention, analytics, routing, artwork size or substrate require review and regression testing.

Closure sequence:

Never let a retired QR resolve to a vendor error, unsafe domain, unrelated campaign or expanded purpose.

17. Approval gates

GateApproval statementApproverEvidenceDate
PurposeOne purpose and every field necessary/proportionate__________________Purpose/field inventory__________
PrivacyNotice, collection, use, disclosure, analytics and retention reviewed__________________Review record__________
CommunicationsContact choices, identity, preferences and withdrawal reviewed__________________Review record__________
SecurityPlatform, MFA, access, routing, export, logging and incident controls approved__________________Security checklist__________
AccessibilityDigital journey and equivalent fallback pass__________________Test evidence__________
ServiceOwner, queue, cover, response commitment and escalation live__________________Routing/roster__________
ProductionPayload, proof, destination and artwork versions match__________________Test log/proof__________
ReleaseAll gates complete for exact version__________________Signed release record__________

18. Final preflight and evidence pack

Evidence pack:

  1. purpose/applicability and field-minimisation records;
  2. exact notice and choice wording;
  3. privacy, communications, security and accessibility reviews;
  4. platform, vendor, location, access and retention records;
  5. canonical URL, short route, QR payload and attribution manifest;
  6. source QR master, final artwork and physical-proof evidence;
  7. device, browser, network, accessibility, routing and print logs;
  8. approval/release record and responder roster;
  9. change history; and
  10. decommission/deletion evidence.

Until all applicable gates pass for the exact production version, this derivative remains REVIEW.