Privacy Policy
Privacy Policy for AuditnQ and related websites operated by Rendering Consulting Inc.
Attorney-review draft. Not legal advice. Not final for production Stripe charges. Align company name, address, and contact email with your Stripe business profile and the Japanese Privacy Policy at ren-con.jp/privacy-policy-jp.
Last updated: 2026-07-29
Rendering Consulting Inc. (RenderingConsulting株式会社; “Company,” “we,” “us,” or “our”) provides enterprise software/SaaS (including AuditnQ, AuditnQA, and AuditnA), management consulting and business development support, creative planning/production/distribution support, and related activities. This Privacy Policy explains how we handle personal information in those activities.
Terms such as “personal information” are used in a manner consistent with applicable law (including Japan’s Act on the Protection of Personal Information where it applies). If you are in the EEA, UK, Switzerland, or California, you may also use our English request form: Data subject and consumer requests.
SaaS processor boundary. Personal data that a customer registers, enters, or uploads into our SaaS (including AuditnQ / AuditnQA / AuditnA) is, in principle, handled by that customer as the business / controller. We process that data as a service provider / processor under our contract with the customer. Requests to access, correct, or delete that data are, in principle, directed to the relevant customer. See also Sections 4 and 6 below and the data-requests page.
1. Information we collect
We may collect personal information including:
Name, address, employer, department, title, telephone/fax, email address, bank account information, credit card numbers (typically via payment processors), photographs, audio, video, and product/service contracting information.
Recruiting. For applicants we may also collect education, work history, qualifications, current compensation, disability certificate status, residence status, portfolio materials, interview communications, application history, and selection outcomes.
Sole proprietors / speakers. We may collect Individual Numbers (My Number) where required for Japanese tax withholding and related filings.
Website security. Forms may use Google reCAPTCHA v3. Google’s privacy policy and terms apply; device/app data may be sent to Google for spam protection and security.
Cookies. We use cookies for site functionality and analytics:
- Essential cookies — required for basic site operation.
- Analytics cookies — Google Analytics (traffic data; not used to identify you personally in our analytics configuration). Prefer-in via the cookie banner where shown; you may also disable cookies in your browser (some features may break).
2. Purposes of use
We use personal information as needed for the purposes below. If a new purpose arises outside this list, we will obtain consent when required or otherwise publish the purpose as required by law.
(1) Customers and prospects
- Product/service information (new features, improvements, case studies)
- Seminars and events
- Contracting, account changes, renewals, cancellations, and transaction records
- Quotes and billing
- Thank-you communications after purchase
- Product surveys and related prizes (if any)
- Maintenance and incident notices
- Customer support and inquiry responses
- Certification programs, user/developer communities (if offered)
- Product improvement analytics
- Marketing and support effectiveness measurement
(2) Business partners (including channel partners)
- Partner record management
- Contracting and operational communications
- Invoicing and payments
(3) Security vulnerability / incident reporters
- Communications with reporters
- Bug bounty participation and payments (if applicable)
- Vulnerability research environment programs (if applicable)
(4) Job applicants
- Recruiting communications
- Selection process
- Prior application history checks
- Applicant record management
(5) Employees and former employees
- HR and payroll
- Social insurance and tax compliance
(6) Media and other individuals
- Communications
- Seminars and events
(7) Common purposes
- Legal compliance
- Establishing or defending legal rights
- Corporate transactions (merger, acquisition, asset sale)
3. Sharing with third parties
We do not provide personal data to third parties without prior consent, except where:
- Needed for billing/payment processors in connection with fees
- Needed for co-hosted seminars/events (participant data shared with co-hosts)
- Needed to protect rights, property, or services against Terms violations
- Required by law
- Necessary to protect life, body, or property and consent is difficult to obtain
- Necessary for public health or child welfare and consent is difficult to obtain
- Necessary to cooperate with government authorities where seeking consent would impede the duty
4. Entrustment (processors and subprocessors)
We may entrust handling of personal data to external providers. We select providers that maintain adequate protection, contract for data protection, and supervise them appropriately.
Customer SaaS data. Where we process personal data on a customer’s SaaS tenant under their instructions, our role and how disclosure requests are handled are described in the opening SaaS processor boundary above. If we further entrust that processing to subprocessors, this Section 4 applies.
Payment processing (for example Stripe) is typically arranged for our own billing relationship; card data should not be uploaded into questionnaire answers or other tenant content.
5. Security measures
We take administrative, technical, and physical measures to prevent leakage, loss, or damage of personal data, including policies, access control, training, facility controls, system protections, and awareness of foreign cloud hosting locations when data may be stored outside Japan.
We maintain an information security management system and have obtained ISO/IEC 27001:2022 certification (registration IS 805180, BSI; scope covering our services). See also our security policy.
6. Access, correction, suspension, and complaints
For personal data we process on behalf of a customer in SaaS (including AuditnQ tenant content), disclosure, correction, and deletion requests are, as stated above, generally directed to that customer.
For retained personal data we handle as a business / controller, you may request disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of third-party provision within the scope of applicable law. Contact us via Section 8. EEA/UK/Swiss/California residents may also use the data-requests form.
7. Changes
We may revise this Policy without prior notice to reflect legal or business changes. The “Last updated” date will change when we do.
8. Contact
Privacy inquiries: use the Contact page, or email [email protected].
Rendering Consulting Inc. (RenderingConsulting株式会社)
Personal information inquiry desk