Data Processing Addendum
AuditnQ Data Processing Addendum for Customer Personal Data processed as a processor.
Last updated: 2026-07-30
Version: 2026-07-30.1
This Data Processing Addendum, together with Annexes 1–3 and Exhibit A (collectively, this “DPA”), supplements the AuditnQ SaaS Terms (or another written agreement that expressly incorporates this DPA) between Rendering Consulting Inc. (“Provider,” “we,” “us,” or “our”) and the Customer that accepts the Agreement (“Customer,” “you,” or “your”). Provider and Customer may each be referred to as a “Party” and together as the “Parties.”
1. Purpose and incorporation
1.1 Agreement. This DPA forms part of the Agreement and applies only to Provider’s Processing of Customer Personal Data as a Processor (or Service Provider) in connection with the Services.
1.2 Controller activities out of scope. This DPA does not apply to Personal Data for which Provider acts as a Controller or Business (for example, marketing-site visitors, billing contacts Provider manages for its own records, recruiting, or Cookie analytics). Those activities are described in our Privacy Policy.
1.3 Roles. With respect to Customer Personal Data, Customer is the Controller (or Business) and Provider is the Processor (or Service Provider), except where Data Protection Laws assign different roles. Answer Data submitted by Vendor Invitees is Customer Personal Data of the inviting Customer’s Tenant; Customer remains Controller for that data.
1.4 Order of precedence. For Processing of Customer Personal Data, if there is a conflict: (i) the SCCs (where applicable) prevail; then (ii) this DPA; then (iii) the Agreement (including any Order). For all other subjects, the Agreement controls as stated there.
1.5 Acceptance. Customer accepts this DPA by (a) clicking to accept Terms or checkout that reference this DPA, (b) executing an Order that incorporates this DPA, or (c) continuing to use the Services after we notify Customer that this DPA applies to the subscription.
2. Definitions
“Agreement” means the AuditnQ SaaS Terms (or other written agreement incorporating this DPA), together with any Order and policies incorporated by reference.
“Customer Personal Data” means Customer Content that is Personal Data Processed by Provider on Customer’s behalf in the Services. It does not include Personal Data for which Provider acts as Controller.
“Data Protection Laws” means privacy and data-protection laws applicable to the Processing of Customer Personal Data under the Agreement, including where applicable the EU GDPR, UK GDPR / Data Protection Act 2018, Swiss FADP, the Australian Privacy Act 1988, and US State Data Protection Laws, each as amended.
“Data Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed under the Agreement.
“Relevant Communication” means (i) a validated request from a Data Subject to exercise rights under Data Protection Laws regarding Customer Personal Data, or (ii) a complaint, notice, or communication from a Data Subject, Supervisory Authority, or other competent body relating to such Processing.
“SCCs” means the European Commission Standard Contractual Clauses for the transfer of personal data to third countries (Commission Implementing Decision (EU) 2021/914), including where applicable the UK International Data Transfer Addendum and Swiss adaptations described in Exhibit A.
“Sensitive Personal Data” means Personal Data of a sensitive nature, including special categories under GDPR, data relating to children, full payment-card data, bank-account secrets, government-issued identification numbers (including Japanese Individual Numbers / My Number), biometric identifiers used for unique identification, and similar categories under applicable law.
“Subprocessor” means a third party engaged by Provider to Process Customer Personal Data in connection with the Services.
“US State Data Protection Laws” means applicable US state privacy laws, including the CCPA as amended by the CPRA and similar state laws.
Capitalized terms used but not defined in this DPA have the meanings in the Agreement. “Controller,” “Processor,” “Business,” “Service Provider,” “Personal Data,” “Process,” “Sell,” “Share,” “Data Subject,” and “Supervisory Authority” have the meanings given in applicable Data Protection Laws.
3. Customer responsibilities
3.1 Lawful instructions and notices. Customer will comply with Data Protection Laws as Controller, and will ensure it has a lawful basis and all required notices, consents, and rights to transfer Customer Personal Data to Provider and to permit Processing under this DPA (including for Vendor Invitees and individuals whose data appears in Questionnaires, Answer Data, vendor records, or uploads).
3.2 Sensitive Personal Data. Customer will not use the Services to collect, store, or solicit Sensitive Personal Data, unless the Parties agree otherwise in a signed writing that may include additional terms. Customer is solely responsible for claims arising from Customer’s breach of this Section 3.2.
3.3 No payment-card data in the Tenant. Payment-card data for Fees is processed through Provider’s payment processor for Provider’s billing relationship and must not be uploaded into Questionnaires, Answer Data, or other Tenant content.
3.4 Instructions. Customer’s documented instructions for Processing are set out in the Agreement, this DPA, and Customer’s use of the Services (including Tenant configuration and invitations). Customer will not instruct Provider to Process Customer Personal Data in violation of Data Protection Laws.
4. Terms of Processing
4.1 Details. The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Annex 1.
4.2 Provider obligations. Provider will:
- Documented instructions. Process Customer Personal Data only on Customer’s documented instructions (including this DPA and the Agreement), unless required by law to which Provider is subject; in that case Provider will inform Customer of the legal requirement before Processing where legally permitted.
- Confidentiality. Ensure persons authorized to Process Customer Personal Data are under confidentiality obligations.
- Unlawful instructions. Inform Customer if, in Provider’s reasonable opinion, an instruction infringes Data Protection Laws. Provider need not carry out that Processing and will not be in breach of the Agreement solely for declining it.
- Relevant Communications. Upon receiving a Relevant Communication regarding Customer Personal Data and identifying Customer as Controller, notify Customer without undue delay (and in any event within five (5) business days). Provider may refuse the request, provide Customer’s contact information, and direct the requester to Customer. Customer remains responsible for responding. Individuals may also be directed via our data subject and consumer requests page, which describes Processor forwarding.
- Assistance. Taking into account the nature of Processing and information available to Provider, provide reasonable assistance to Customer, at Customer’s expense unless the need for assistance arises from Provider’s breach of this DPA, with: security of Processing; Data Subject requests; Data Protection Impact Assessments and consultations with authorities, in each case to the extent required by Data Protection Laws.
- Records. Maintain records reasonably necessary to demonstrate compliance with this DPA and, on written request, provide information reasonably required for that purpose.
4.3 No secondary use. Provider will not use Customer Personal Data to train, fine-tune, or improve general-purpose or cross-customer machine learning or artificial intelligence models, or for Provider’s own marketing to Data Subjects. Tenant-scoped features that Process Customer Personal Data solely to deliver the Services to that Customer remain permitted.
5. Security
5.1 Measures. Provider will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, taking into account the state of the art, costs, and the nature, scope, context, and purposes of Processing (including measures aligned with Article 32 GDPR where applicable). A summary appears in Annex 2. Current certifications, control descriptions, and related Trust materials are published in our Trust Center and security policy (JP) (informational; not an SLA unless an Order states otherwise). Provider maintains an ISMS and ISO/IEC 27001:2022 certification (registration IS 805180, BSI; scope covering our services).
5.2 Data Security Incidents. After confirming a Data Security Incident, Provider will:
- notify Customer in writing without undue delay (and will aim to do so within seventy-two (72) hours of confirmation where feasible);
- provide cooperation and information reasonably available to Provider;
- not notify Data Subjects or Supervisory Authorities about the Incident on Customer’s behalf without Customer’s prior written consent, except where Provider is legally required to notify, or where Provider notifies parties regarding Personal Data for which Provider is Controller;
- take reasonable steps to mitigate the Incident and prevent recurrence.
Provider will have no liability under this Section 5.2 to the extent the Incident was caused by Customer or Customer’s instructions, Authorized Users, or Vendor Invitees.
6. Subprocessors
6.1 General authorization. Customer provides a general authorization for Provider to engage Subprocessors (including Affiliates) to Process Customer Personal Data as reasonably necessary to provide the Services. Provider remains liable for Subprocessors’ acts and omissions under this DPA as if Provider’s own.
6.2 Contracts. Provider will impose data-protection obligations on each Subprocessor no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the Subprocessor’s services.
6.3 List and notice. Provider maintains a current list of Subprocessors in the Trust Center (the “Subprocessor List”). Provider will update that list and provide at least thirty (30) days’ prior notice (including by updating the list and, where offered, email subscription or Trust Center notification) before a new Subprocessor Processes Customer Personal Data, except for urgent replacements needed for security or continuity, in which case Provider will notify as soon as practicable.
6.4 Objection. Customer may object to a new Subprocessor on reasonable data-protection grounds by written notice within thirty (30) days after notice under Section 6.3. The Parties will discuss in good faith. If they cannot resolve the objection, Customer’s sole remedy is to terminate the affected Services (or the Agreement if the Services cannot reasonably be provided without that Subprocessor) upon written notice; prepaid unused Fees for the terminated portion of the then-current term will be refunded on a pro-rata basis.
7. US state privacy (CCPA/CPRA and similar)
To the extent US State Data Protection Laws apply to Customer Personal Data:
7.1 Provider is a Service Provider (or equivalent) and Customer is a Business (or equivalent).
7.2 Provider will not: (a) Sell or Share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes of providing the Services under the Agreement, or as otherwise permitted by those laws; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer; or (d) combine Customer Personal Data with Personal Data from other sources except as permitted for those business purposes.
7.3 Transfer of Customer Personal Data to Provider for the Services is not a Sale or Share. Provider certifies that it understands and will comply with the restrictions in this Section 7. If Provider determines it can no longer meet its obligations under this Section, it will notify Customer as required by applicable law. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use upon reasonable written notice.
8. International transfers
8.1 Customer acknowledges that Provider may Process Customer Personal Data in Japan and in other jurisdictions where Provider, its Affiliates, or Subprocessors operate, as needed to provide the Services.
8.2 If Customer Personal Data originating in the EEA, United Kingdom, or Switzerland is transferred to a country that does not provide an adequate level of protection under applicable Data Protection Laws, the Parties enter into and incorporate the SCCs as described in Exhibit A. Where SCCs require supplemental information, Exhibit A and Annexes 1–3 apply.
8.3 If the SCCs relied on are superseded, the Parties will apply the replacement clauses prescribed by the competent authority without needing to amend this DPA, unless a Party objects on reasonable legal grounds and the Parties negotiate an alternative transfer mechanism in good faith.
8.4 In a conflict between this DPA and the applicable SCCs, the SCCs prevail.
9. Return and deletion
9.1 Self-serve export tools, if available, may be used during the Subscription Term. Upon written request within thirty (30) days after termination or expiration of the Agreement, Provider will make Customer Content (including Customer Personal Data) available in a commercially reasonable format (including assisted export if no self-serve tool exists) for up to thirty (30) days, then delete it from production systems within sixty (60) days, subject to backups and legal retention, consistent with Section 11 of the SaaS Terms.
9.2 Provider may retain copies of Customer Personal Data solely as required by law or for insurance, accounting, tax, or record-keeping purposes, and will continue to protect such copies under this DPA until deletion or anonymization.
10. Audit
10.1 No more than once per twelve (12) months (unless required by Data Protection Laws, a Supervisory Authority, or following a Data Security Incident), Customer may audit Provider’s compliance with this DPA by written request for: (a) responses to reasonable security/privacy questionnaires; and/or (b) summaries or reports of relevant certifications or independent audits (including ISO/IEC 27001 materials Provider makes available), subject to confidentiality.
10.2 On-site audits are available only where questionnaires and certifications are reasonably insufficient, upon at least thirty (30) days’ prior written notice, during normal business hours, without unreasonably disrupting operations, and under confidentiality. Customer bears its own costs and any reasonable costs Provider incurs for on-site audits not caused by Provider’s material breach of this DPA.
10.3 Audit information may be used only to verify compliance with Data Protection Laws and this DPA, or to respond to regulators.
11. Term; general
11.1 This DPA applies for as long as Provider Processes Customer Personal Data under the Agreement.
11.2 Notices under this DPA follow the notice provisions of the Agreement (including [email protected]).
11.3 Except as required by the SCCs, this DPA is governed by the governing law and venue of the Agreement.
11.4 Provider may update this DPA by posting a revised version. For material adverse changes affecting paid Customers’ Processing terms, Provider will provide notice consistent with the Agreement’s update provisions; if Customer objects as described in that notice, timely termination with pro-rata refund of prepaid unused Fees is available as stated in the Agreement. This DPA is versioned separately from the Privacy Policy; a Privacy Policy update does not by itself amend this DPA.
11.5 Questions: Contact or [email protected]. Data-subject requests regarding Customer Personal Data should generally go to the Customer; see also data requests.
Annex 1 — Details of Processing
Services / nature and purpose. Hosted AuditnQ / AuditnQA vendor management and third-party risk Services, including Questionnaire management, Project-based answer collection, Vendor Invitee collaboration, vendor/subcontractor relationship graphs, vendor master and risk/analytics views, authentication, support, hosting, backup, and related security monitoring.
Duration. The Subscription Term plus any wind-down, export, and deletion periods under the Agreement and this DPA.
Categories of Data Subjects.
- Customer’s and its Affiliates’ employees, contractors, and admins (Authorized Users)
- Personnel of Customer’s vendors and subcontractors (including Vendor Invitees and contacts)
- Other individuals whose Personal Data appears in Questionnaires, Answer Data, vendor records, relationship graphs, or uploaded files
Types of Customer Personal Data (examples; depends on Customer’s use).
| Category | Examples |
|---|---|
| Identity / contact | Name, email, phone, job title, company, department |
| Account / auth | User identifiers, authentication logs, IP address, MFA status |
| Questionnaire / Answer Data | Responses that may include names or business contact details |
| Uploaded files | Documents that may incidentally contain Personal Data |
| Support | Ticket content that quotes Customer Personal Data |
Types Customer should not submit. Sensitive Personal Data as defined in this DPA (including special-category data, children’s data, government ID numbers such as My Number, full payment-card data, and bank-account secrets), unless agreed in writing.
Processing operations. Collection, storage, hosting, transmission, display, structured retrieval, deletion, backup, security monitoring, support access, and email delivery of invites and notifications.
Annex 2 — Technical and organizational measures (summary)
Provider maintains appropriate technical and organizational measures for the Services (including organizational, people, physical, and technical controls under an ISMS / ISO/IEC 27001:2022, logical Tenant separation, and Subprocessor due diligence). Current descriptions, certifications, and related materials are published in the Trust Center. This Annex is a contractual summary only — not a complete control catalog or SLA.
Annex 3 — Subprocessors
The current Subprocessor List is published in the Trust Center and is incorporated by reference. Section 6 of this DPA governs authorization, notice, and objection.
Exhibit A — Standard Contractual Clauses (summary completion)
Where Section 8 requires SCCs, the Parties are deemed to enter into the SCCs with the following selections. Counsel should confirm these elections before production reliance.
Parties
| Role | Party | Details |
|---|---|---|
| Data exporter | Customer | Address and contact as in the Agreement / Tenant admin or billing contacts |
| Data importer | Rendering Consulting Inc. | Cross-C ShibuyaShinsen Bld.5-6, 20-21, Shinsencho, Shibuya, Tokyo, Japan; [email protected] |
| Activities | Provision of the Services under the Agreement | |
| Roles | Exporter: Controller — Importer: Processor | Module 2 (controller → processor) applies for Customer → Provider transfers |
Modules and options (EU SCCs)
- Module 2 (controller to processor) applies to transfers described above. Module 3 applies only if Provider acts as a processor transferring to a sub-processor in a restricted third country in a manner requiring Module 3 (Subprocessor contracts address onward transfers).
- Clause 7 (Docking): optional docking clause does not apply.
- Clause 9 (Subprocessors): Option 2 — general written authorization; list and notice period as in Section 6 and the Trust Center Subprocessor List.
- Clause 11(a) (Redress): optional language does not apply.
- Clause 17 / 18: Option 1 — governing law and forum of Ireland for EEA transfers (or as required for Swiss/UK adaptations below), solely for the SCCs.
- Annex I description of transfer: Annex 1 of this DPA; transfers on a continuous / ongoing basis as needed for the Services.
- Annex II TOMs: Annex 2 of this DPA and the Trust Center.
- Annex III Subprocessors: Trust Center.
- Competent Supervisory Authority (EEA): Irish Data Protection Commission, unless another authority is mandatory for the exporter.
UK transfers
For UK transfers, the EU SCCs as completed above are supplemented by the UK International Data Transfer Addendum (Version B.1.0, or successor). Tables are completed by reference to this DPA, the Agreement, Annexes 1–3, and this Exhibit. Clause 9 is general authorization as in Section 6. Table 4 (ending the Addendum): Importer.
Swiss transfers
References to the GDPR are interpreted to include the Swiss FADP where applicable. The Swiss Federal Data Protection and Information Commissioner is an additional competent authority. Where the transfer is exclusively subject to the FADP, Swiss law and Swiss forums apply for Clauses 17 and 18 as required by Swiss guidance; “member state” includes Switzerland for Data Subject rights under the FADP.
Conflict
If this Exhibit conflicts with the official SCC text, the official SCC text prevails.