M-T1-CP-04-SD-03 — QR Contact Form Setup Guide
Release control
| Field | Controlled value |
|---|---|
| Status | REVIEW — configured derivative; privacy, communications, security, accessibility, service and production approval required before publication |
| Supporting-document code | M-T1-CP-04-SD-03 |
| Exact derivative title | QR Contact Form Setup Guide |
| Source initiative | M-T1-CP-04 - Pop-Up Rotary Displays |
| Source initiative code | M-T1-CP-04 |
| Source initiative title | Pop-Up Rotary Displays |
| Initiative disposition | Canonical retained |
| Canonical parent | M-T1-CP-04 - Pop-Up Rotary Displays |
| Canonical parent code and title | M-T1-CP-04 - Pop-Up Rotary Displays |
| Named overlay or migration label | Canonical static-display body |
| Redirect or tombstone route | None |
| Family master | Playbook_F11_Digital_QR_Data_Capture_Master.md |
| Family / master version | F11 / 1.0 |
| Recorded master SHA-256 | e9f831e4adda1cd5f17f244cea7bfc694b3c1ce6562f5c0272db613a4f2eba29 |
| Authoritative index | Playbook_Supporting_Documents_Master_Index.md v1.1 |
| Configured master variant | F11 controlled Playbook asset — single mapped Pop-Up Rotary Displays derivative |
| Derivative version | v0.1 |
Adaptation note
This derivative configures the canonical static-display QR journey for Pop-Up Rotary Displays. It connects one clear public action to a minimal, accessible form; separates requested operational contact from optional future updates; uses an organisation-controlled HTTPS destination and visible short route; records privacy, security, routing, retention and decommissioning controls; engineers the QR from the final payload; and requires production-equivalent device, accessibility, network, print and follow-up testing before launch.
Privacy, communications and legal boundary. This is operational guidance, not legal advice. The host entity must obtain current review appropriate to its legal status, activity, audience, platforms and jurisdictions. Do not assume an exemption from Australian privacy, electronic-message or other obligations. Record the local determination and conditions.
1. Instructions and non-negotiable release rule
- Declare one primary purpose and public action. Remove collection where public information can meet the need.
- Record a necessity, access role, required/optional decision and retention link for every field before opening the form builder.
- Resolve the host, data owner, privacy/communications/security/accessibility reviewers, follow-up owner, incident lead and approver.
- Configure the form, notice, choices, routing, preferences, security, retention and safe closed state in a production-equivalent environment.
- Freeze and peer-check the exact destination and attribution values before generating the QR.
- Produce a vector QR master, accessible lock-up, visible typed route and actual-size physical proof.
- Execute every applicable digital, routing, accessibility, network, device and print test and retain evidence for the exact version.
- Sign all approval gates, conduct a live installed scan, monitor the service and decommission safely.
If a required owner, gate, test or evidence item is absent, the public QR does not ship. A scan that opens a page is not proof that the complete service works.
2. Controlled configuration fields
Identity, approval and ownership
| Controlled field | Resolved value | Source / evidence | Owner | Verified date |
|---|---|---|---|---|
| Local derivative / form name | __________________ | __________________ | __________________ | __________ |
| Host entity and public contact | __________________ | __________________ | __________________ | __________ |
| Data Owner / Form Owner | __________________ | __________________ | __________________ | __________ |
| System Administrator | __________________ | __________________ | __________________ | __________ |
| Privacy / Communications Reviewers | __________________ | __________________ | __________________ | __________ |
| Security / Accessibility Reviewers | __________________ | __________________ | __________________ | __________ |
| Follow-up Owner / cover | __________________ | __________________ | __________________ | __________ |
| Incident Lead | __________________ | __________________ | __________________ | __________ |
| Final Approver | __________________ | __________________ | __________________ | __________ |
| Immutable version / approval date | __________________ | __________________ | __________________ | __________ |
| Next review / decommission date | __________________ | __________________ | __________________ | __________ |
Purpose, audience and choices
| Controlled field | Resolved value |
|---|---|
| Primary purpose — one plain-language outcome | ______________________________ |
| Primary display action | ______________________________ |
| Intended audience / separately handled groups | ______________________________ |
| Public-information alternative | ______________________________ |
| Explicit sensitive-data exclusions | ______________________________ |
| Under-18 / welfare / safeguarding route | ______________________________ |
| Collection notice version | ______________________________ |
| Privacy-policy route | ______________________________ |
| Operational response choice | ______________________________ |
| Separate optional future-updates choice | ______________________________ |
| Choice wording version / timestamp / source | ______________________________ |
| Preference / withdrawal / suppression routes | ______________________________ |
Destination, QR, service and lifecycle
| Controlled field | Resolved value |
|---|---|
| Canonical HTTPS URL | ______________________________ |
| Visible human-readable short URL | ______________________________ |
| Exact QR payload | ______________________________ |
| QR filename / version | ______________________________ |
| Finished size / module / quiet zone | ______________________________ |
| Foreground/background / contrast result | ______________________________ |
| Error correction and reason | ______________________________ |
| Print context / substrate / finish / lighting | ______________________________ |
| Intended and tested scan distance | ______________________________ |
| Redirect owner / peer-approval / expiry | ______________________________ |
| Attribution source / medium / campaign / content | ______________________________ |
| Internal display source code | ______________________________ |
| Follow-up queue / owner / service level / escalation | ______________________________ |
| Platform / vendor / data location | ______________________________ |
| Access roles / MFA / logging / export route | ______________________________ |
| Retention trigger / period / deletion route | ______________________________ |
| Incident route | ______________________________ |
| Analytics purpose / bot-test filter / reporting cadence | ______________________________ |
| Safe closed-page URL / archive route | ______________________________ |
Never infer an owner, legal status, data location, response commitment or retention period.
3. Purpose and data-minimisation gate
| Decision question | Pass condition | Local evidence | Pass |
|---|---|---|---|
| Can public information meet the need without collection? | No form on that pathway, or collection justified | __________________ | [ ] |
| Can the action be anonymous? | Anonymous route offered where workable | __________________ | [ ] |
| Is there exactly one declared primary purpose? | Specific, current and visible | __________________ | [ ] |
| Does every field directly support that purpose? | One-sentence necessity for each | __________________ | [ ] |
| Is each required field genuinely necessary? | Operational reason and consequence documented | __________________ | [ ] |
| Is a lower-risk data type sufficient? | Lower-risk option selected | __________________ | [ ] |
| Is speculative “useful later” collection absent? | No open-ended future-use field | __________________ | [ ] |
| Are free-text fields removed or tightly constrained? | Purpose, include/exclude instruction, limit and restricted route | __________________ | [ ] |
| Are higher-risk data excluded or separately approved? | Identity, financial, credential, health, criminal and precise-location data excluded by default | __________________ | [ ] |
Stop rule: remove a field whose necessity cannot be stated in one clear sentence.
4. Form journey
| Screen / section | Purpose | Configured content |
|---|---|---|
| 1. Landing | Confirm host, purpose and right destination | Host identity, form name, action, time estimate, public-information option |
| 2. Interest | Choose a serviceable next step | Short controlled interest list |
| 3. Contact | Collect only the selected reply channel | Preferred method and conditional email/phone/other field |
| 4. Context | Capture essential routing detail | Constrained values; approved limited text only |
| 5. Choices | Separate requested reply from future updates | Independent, unbundled choices |
| 6. Notice | Explain collection before submission | Host, purpose, handling, consequence, policy and privacy contact |
| 7. Submit | State the actual action | “Request information” or other approved specific label |
| 8. Confirmation | Confirm receipt and next step safely | Service level, public resources, preference route; no submitted data echoed |
5. Field specification
| Field ID | Visible persistent label | Type | Required? / reason | Data category | Help / include-exclude | Validation / error | Logic | Access | Retention link |
|---|---|---|---|---|---|---|---|---|---|
| F-01 | Area of interest | Controlled choice | Required / routing | Preference | Choose one current option | Select one option / Explain recovery | Always | Follow-up roles | __________________ |
| F-02 | Preferred contact method | Controlled choice | Required / reply | Contact preference | Choose available route | Select one / Explain recovery | Always | Follow-up roles | __________________ |
| F-03 | Email or phone for selected method | Appropriate input | Required only for selected method | Contact detail | Enter only chosen reply detail | Format rule / Specific recovery | Conditional | Follow-up roles | __________________ |
| F-04 | Essential context | Controlled choice / limited text | Optional or justified | Enquiry context | State what not to include | Character limit / recovery | Approved only | Restricted queue | __________________ |
| F-___ | __________________ | __________________ | __________________ | __________________ | __________________ | __________________ | __________________ | __________________ | __________________ |
Field rules:
- [ ] Persistent labels are used; placeholders are not the only labels.
- [ ] Preferred name is used unless full/legal name is necessary.
- [ ] Only the contact field for the selected method appears.
- [ ] No phone number is forced where another selected method works.
- [ ] No account, app or third-party sign-in is required.
- [ ] Passwords, access codes and payment-card data are never requested.
- [ ] Safe entered values persist after an error.
6. Routing categories
| Visitor need | Minimum useful collection | Route / owner | Control |
|---|---|---|---|
| Learn more | None | Public information | Prefer no collection |
| Ask a question | Contact method/detail and constrained topic | General enquiry queue: __________ | Limit open text |
| Attend a meeting | Contact method and meeting/location preference | Meeting owner: __________ | No automatic future updates |
| Volunteer or join an activity | Contact method and opportunity category | Volunteer owner: __________ | Apply safeguarding route |
| Invite a speaker | Contact, organisation and broad event window | Speaker coordinator: __________ | Collect detailed logistics later |
| Explore partnership | Contact, organisation and broad interest | Partnership owner: __________ | Proposals outside public form |
| Accessibility support | Preferred contact and assistance route | Accessibility contact: __________ | Do not request diagnosis |
| Privacy/data request | Direct privacy contact | Privacy function: __________ | Do not route through marketing |
Offer only categories the host can service.
7. Collection notice and independent choices
Reviewed notice structure
About this form
[Host entity] collects the information you choose to provide so we can [primary purpose]. If you do not provide a required item, [specific consequence]. Your response is sent to [owned route] and handled under our privacy information at [privacy-policy route]. For a privacy question or request, contact [host contact]. Any choice about future updates is optional and separate from the response you are requesting.
Add locally required disclosures about collection circumstances, usual or overseas disclosure, access/correction and complaint handling. Essential information stays in the form; a policy link does not carry the whole explanation.
Operational response
- [ ] “Please contact me about the option I selected.”
This governs the requested service response only.
Separate future updates
- [ ] “I would also like optional future updates from [identified sender] using [identified channel]. I can change this choice through [route].”
The future-updates choice is optional, unselected by default, versioned, timestamped and not a condition of the requested response.
Confirmation
Your request has been received. We aim to respond within [approved service level]. For public information, visit [route]. To change an optional future-updates choice, use [preference route].
Do not echo submitted contact details or private context.
8. Accessibility and equivalent fallback
Digital checks:
- [ ] Descriptive page title, headings and landmarks.
- [ ] Persistent programmatic labels and instructions before input.
- [ ] Full keyboard operation, logical order and visible focus.
- [ ] Text error summary and field errors linked to controls.
- [ ] Colour is not the only cue; contrast and 200% zoom/reflow pass.
- [ ] Screen-reader name, role, state, help, errors and confirmation pass.
- [ ] No motion, pointer gesture or image-only challenge is required.
- [ ] Timeouts are removed or can be extended without data loss.
Fallback:
| Route | Notice and choices preserved | Custody | Secure transcription | Original disposal |
|---|---|---|---|---|
| Typed short URL | Same digital journey | N/A | N/A | N/A |
| Assisted completion | Read essential notice; preserve independent choices | Authorised helper | Approved system | No informal notes |
| Paper form | Same minimum fields/notice/choices | Named custodian | Dual-checked route | Approved secure disposal |
| Telephone or email alternative | Collect only necessary information | Named responder | Restricted queue | Approved route |
Scanning is never the only way to act.
9. Canonical destination, redirect and attribution
Destination acceptance:
- [ ] HTTPS and organisation-controlled or contractually governed.
- [ ] No account or app required.
- [ ] Host and purpose appear before collection.
- [ ] Works in supported mainstream mobile browsers.
- [ ] No personal information, access token, secret or submitted value in URL.
- [ ] Stable ownership, renewal and safe closed response are recorded.
Short route acceptance:
- [ ] Legible, memorable, typeable and recognisably associated with the host.
- [ ] Resolves to the same approved journey.
- [ ] Avoids ambiguous characters where practical.
- [ ] Owner, peer approval, change log and expiry/review date recorded.
| Payload control | Release value |
|---|---|
| Exact encoded payload | ______________________________ |
| Canonical destination | ______________________________ |
| Visible short route | ______________________________ |
| Attribution source | pop_up_display / approved value: __________ |
| Medium | qr |
| Campaign | ______________________________ |
| Content / placement variant | ______________________________ |
| Internal display source | ______________________________ |
| Redirect owner / expiry | ______________________________ |
Attribution values contain no name, email, phone, membership identifier, secret or sensitive location. Never repoint a printed QR to an unrelated purpose.
10. QR engineering and artwork specification
- Resolve and peer-check the exact payload.
- Open it directly in a private browser and confirm host, certificate, page and attribution.
- Generate a standards-conformant QR from that exact string.
- Record error correction based on payload density and production risk.
- Bind immutable master filename and QR version.
- Export vector for print and lossless high-resolution raster only where required.
Never generate, recreate, trace or upscale the QR with an image-generation tool.
| Attribute | Configured production requirement | Evidence |
|---|---|---|
| Payload | URL only; no personal data, secret or raw response | __________________ |
| Master format | SVG, PDF or EPS vector; crisp square modules | __________________ |
| Raster, if required | Lossless PNG at sufficient resolution for at least 300 ppi at placed size | __________________ |
| Starting hand-held size | At least 25 mm square before density/context adjustment; final proof controls | __________________ |
| Final size / module | ______________________________ | __________________ |
| Quiet zone | At least four modules on every side | __________________ |
| Colour / contrast | Dark symbol on plain light background; recorded result | __________________ |
| Distortion | No stretch, skew, crop, rotation, warp or non-uniform scaling | __________________ |
| Decoration | No logo, icon, photo, gradient or texture inside the symbol unless separately engineered and exhaustively tested | __________________ |
| Placement | Flat, unobstructed, away from fold, trim, curve and glare | __________________ |
| Label | Specific action plus visible typed short route | __________________ |
| Context / distance | Actual substrate, finish, light and intended range | __________________ |
If an official Rotary mark is placed adjacent to the QR, use only the supplied original asset, preserve its colours and proportions, account for transparent padding and keep it entirely outside the QR quiet zone. Do not generate, substitute or stretch a mark.
Print handoff includes the immutable vector master, exact size, locked aspect ratio, quiet-zone/no-crop/no-effects instructions, contrast/background, substrate/finish/light, proof approver and mandatory physical scan test. A screenshot of a QR is not a production master.
11. Device, network, accessibility and print test log
| Test ID | Scenario | Device / browser / network / print condition | Expected | Actual | Result | Evidence | Tester / date |
|---|---|---|---|---|---|---|---|
| QR-001 | Typed canonical, short, tagged and untagged routes | __________________ | Correct host, notice and source | __________________ | Pass / Fail | __________________ | __________________ |
| QR-002 | Current supported iOS cameras | __________________ | Detect and open correct route | __________________ | Pass / Fail | __________________ | __________________ |
| QR-003 | Current supported Android cameras | __________________ | Detect and open correct route | __________________ | Pass / Fail | __________________ | __________________ |
| QR-004 | Private browser / no account | __________________ | Complete without barrier | __________________ | Pass / Fail | __________________ | __________________ |
| QR-005 | Cellular, Wi-Fi and constrained network | __________________ | Useful first content; no duplicate | __________________ | Pass / Fail | __________________ | __________________ |
| QR-006 | Offline / captive portal / service failure | __________________ | Typed and assisted fallback visible | __________________ | Pass / Fail | __________________ | __________________ |
| QR-007 | Keyboard, focus, zoom and reflow | __________________ | Full completion | __________________ | Pass / Fail | __________________ | __________________ |
| QR-008 | Screen reader, labels and errors | __________________ | Correct name/role/state/recovery | __________________ | Pass / Fail | __________________ | __________________ |
| QR-009 | Required, malformed, maximum and corrected values | __________________ | Specific recovery; one valid record | __________________ | Pass / Fail | __________________ | __________________ |
| QR-010 | Operational/future choices | __________________ | Independent stored values/version | __________________ | Pass / Fail | __________________ | __________________ |
| QR-011 | Each interest route and service due date | __________________ | Correct owner and alert | __________________ | Pass / Fail | __________________ | __________________ |
| QR-012 | Preference/withdrawal/suppression | __________________ | End-to-end correct action | __________________ | Pass / Fail | __________________ | __________________ |
| QR-013 | Actual-size substrate proof | __________________ | Reliable quiet zone/contrast scan | __________________ | Pass / Fail | __________________ | __________________ |
| QR-014 | Near/intended/far, angle and expected light/glare | __________________ | Reliable in approved envelope | __________________ | Pass / Fail | __________________ | __________________ |
| QR-015 | Closed form and retired redirect | __________________ | Safe closed page; no collection | __________________ | Pass / Fail | __________________ | __________________ |
Blocker or high defects must close and affected regression tests repeat before release. An exception cannot waive privacy, security, destination, accessibility or response ownership.
12. Ownership and routing
| Interest category | Destination | Named owner | Service level | Escalation | Out-of-office cover | Closure definition |
|---|---|---|---|---|---|---|
| __________________ | __________________ | __________________ | __________________ | __________________ | __________________ | __________________ |
| __________________ | __________________ | __________________ | __________________ | __________________ | __________________ | __________________ |
For every accepted submission: assign category, calculate due date, alert only the authorised route, acknowledge safely, record action/completion, keep future-update preference separate and escalate aged/sensitive cases. Never distribute raw responses to a club-wide list or use a publicly linked spreadsheet as the queue.
13. Platform, security, access and retention gate
| Control | Approved value / evidence | Reviewer | Pass |
|---|---|---|---|
| Platform/vendor/contract and data location | __________________ | __________________ | [ ] |
| Individual accounts and least privilege | __________________ | __________________ | [ ] |
| Multi-factor authentication | __________________ | __________________ | [ ] |
| Administrator, responder, export and audit roles | __________________ | __________________ | [ ] |
| Integration/webhook/API credential controls | __________________ | __________________ | [ ] |
| Logging, backup and recovery | __________________ | __________________ | [ ] |
| Approved logged export route | __________________ | __________________ | [ ] |
| Retention trigger and period by data category | __________________ | __________________ | [ ] |
| Deletion/de-identification and backup treatment | __________________ | __________________ | [ ] |
| Suppression/do-not-contact preservation | __________________ | __________________ | [ ] |
| Incident route and responder exercise | __________________ | __________________ | [ ] |
Working exports are exceptional, logged, access-limited, time-bound and securely removed after approved transfer.
14. Incident response
- contain exposure or misrouting through authorised controls;
- preserve relevant logs, configuration, screenshots and version identifiers without uncontrolled copies;
- assess information, people, systems, access, consequences and ongoing risk;
- escalate to approved privacy, security, legal, records, communications and leadership routes;
- make notification decisions under current law and qualified advice;
- communicate verified facts and practical protective steps;
- validate destination, form, access, routing and preferences before reopening; and
- record cause, impact, decisions, actions, owners and prevention.
| Incident reference | Date/time | Immediate containment | Version / system | Escalated to | Reopen authority | Restricted evidence |
|---|---|---|---|---|---|---|
| __________________ | __________________ | __________________ | __________________ | __________________ | __________________ | __________________ |
15. Analytics and service reporting
| Measure | Formula / source | Denominator and exclusions | Interpretation |
|---|---|---|---|
| QR landing sessions | Eligible governed-source sessions after bot/test filter | __________________ | A session is not necessarily a person |
| Form starts | First meaningful form interaction | __________________ | Define test exclusions |
| Completed submissions | Accepted non-test submissions | __________________ | Remove duplicates by documented rule |
| Completion rate | Completed ÷ eligible starts | __________________ | Journey measure, not impact |
| Future-updates selection | Affirmative valid choices ÷ eligible submissions shown choice | __________________ | Not a quality score |
| Follow-up within service level | Timely actions ÷ eligible routed responses | __________________ | Define pauses/exclusions |
| Next-step conversion | Defined next step ÷ eligible responses | __________________ | State observation window |
| Error / fallback use | Defined errors or assisted/paper uses | __________________ | Do not infer disability or preference |
Small-number reporting must prevent re-identification. Scans and submissions are not community impact.
16. Change control and decommissioning
| Version | Change / reason | Risk and reviews | Regression tests | Approver / date | Supersedes |
|---|---|---|---|---|---|
| __________________ | __________________ | __________________ | __________________ | __________________ | __________________ |
Material changes to purpose, audience, field, notice, choice, platform, URL/payload, access, retention, analytics, routing, artwork size or substrate require review and regression testing.
Closure sequence:
- [ ] Locate remaining printed assets from the display manifest.
- [ ] Stop new submissions at the approved time.
- [ ] Route QR and typed short URL to the safe closed page.
- [ ] State closure and provide safe public-information/contact alternative.
- [ ] Complete/transfer open follow-ups and preserve suppression.
- [ ] Remove integrations, secrets, automation and unnecessary access.
- [ ] Produce only the approved final record.
- [ ] Apply retention/deletion across platform, exports, paper, duplicates and backups.
- [ ] Test QR, short route and canonical route after closure.
- [ ] Archive manifest, approvals, tests, incidents and deletion evidence.
Never let a retired QR resolve to a vendor error, unsafe domain, unrelated campaign or expanded purpose.
17. Approval gates
| Gate | Approval statement | Approver | Evidence | Date |
|---|---|---|---|---|
| Purpose | One purpose and every field necessary/proportionate | __________________ | Purpose/field inventory | __________ |
| Privacy | Notice, collection, use, disclosure, analytics and retention reviewed | __________________ | Review record | __________ |
| Communications | Contact choices, identity, preferences and withdrawal reviewed | __________________ | Review record | __________ |
| Security | Platform, MFA, access, routing, export, logging and incident controls approved | __________________ | Security checklist | __________ |
| Accessibility | Digital journey and equivalent fallback pass | __________________ | Test evidence | __________ |
| Service | Owner, queue, cover, response commitment and escalation live | __________________ | Routing/roster | __________ |
| Production | Payload, proof, destination and artwork versions match | __________________ | Test log/proof | __________ |
| Release | All gates complete for exact version | __________________ | Signed release record | __________ |
18. Final preflight and evidence pack
- [ ] One declared purpose; public-information alternative present.
- [ ] Every field has necessity, category, required status and retention link.
- [ ] Higher-risk data and unrestricted free text excluded or separately approved.
- [ ] Host, purpose, consequence, handling and privacy contact visible before submit.
- [ ] Operational reply and optional future updates remain separate and unselected.
- [ ] Preference, withdrawal and suppression work end to end.
- [ ] Digital accessibility and equal fallback tests pass.
- [ ] Canonical, short and QR routes match the governed destination.
- [ ] Payload/attribution contain no personal information or secrets.
- [ ] Immutable vector/raster masters, size, module, quiet zone, contrast, context and distance are recorded.
- [ ] QR is not cropped, distorted, decorated or recompressed.
- [ ] Actual-size physical proof passes device, angle, light and distance tests.
- [ ] Queue, service, cover, access, MFA, vendor, retention and incident routes are active.
- [ ] Form, notice, choices, QR, redirect, artwork and print versions match one manifest.
- [ ] Installed display passes live scan and typed-route tests.
- [ ] Next review, safe closed route and decommission date are scheduled.
Evidence pack:
- purpose/applicability and field-minimisation records;
- exact notice and choice wording;
- privacy, communications, security and accessibility reviews;
- platform, vendor, location, access and retention records;
- canonical URL, short route, QR payload and attribution manifest;
- source QR master, final artwork and physical-proof evidence;
- device, browser, network, accessibility, routing and print logs;
- approval/release record and responder roster;
- change history; and
- decommission/deletion evidence.
Until all applicable gates pass for the exact production version, this derivative remains REVIEW.
