Privacy Policy

Privacy Policy for AuditnQ and related websites operated by Rendering Consulting Inc.

Last updated: 2026-09-01

Rendering Consulting Inc. (“Company,” “we,” “us,” or “our”) provides enterprise software/SaaS (including AuditnQ, AuditnQA, and AuditnA), management consulting and business development support, creative planning/production/distribution support, and related activities. This Privacy Policy explains how we handle personal information in those activities.

Terms such as “personal information” are used in a manner consistent with applicable law (including Japan’s Act on the Protection of Personal Information where it applies). If you are in the EEA, UK, Switzerland, or California, you may also use our English request form: Data subject and consumer requests.

SaaS processor boundary. Personal data that a customer registers, enters, or uploads into our SaaS (including AuditnQ / AuditnQA / AuditnA) is, in principle, handled by that customer as the business / controller. We process that data as a service provider / processor under our contract with the customer (for Global self-serve subscriptions, see our Data Processing Addendum and Trust Center for subprocessors). Requests to access, correct, or delete that data are, in principle, directed to the relevant customer. See also Sections 4 and 6 below and the data-requests page.


1. Information we collect

This Section 1 describes information we handle as a business / controller. It does not describe personal data a customer registers, enters, or uploads into an AuditnQ tenant (see the SaaS processor boundary above). Do not put payment-card data, bank-account secrets, My Number, or other Sensitive Personal Data in tenant content; see the SaaS Terms and DPA.

This marketing site and inquiries. When you email us or use a form on this site, we may collect name, work email, company, job title, and message content.

Billing. If you subscribe via Stripe, payment-card data is collected by Stripe as our payment processor for our billing relationship. We do not store full card numbers. Card data must not be uploaded into questionnaires, answers, or other tenant content.

Japanese tax (not the SaaS tenant). For sole proprietors or speakers we pay in Japan, we may collect Individual Numbers (My Number) only where required for withholding and related filings. We do not collect My Number through the AuditnQ product tenant.

Business payments. For invoices we pay (for example partners or speakers), we may collect bank-account details needed to pay. We do not collect bank-account secrets through the AuditnQ tenant.

Recruiting. For applicants we may also collect education, work history, qualifications, current compensation, disability certificate status, residence status, portfolio materials, interview communications, application history, and selection outcomes.

Website security. Inquiries may be by email or by a hosted form. When a hosted form is enabled, we may use Google reCAPTCHA v3 for spam protection and security. Google’s privacy policy and terms apply; device/app data may be sent to Google.

Cookies. This marketing site uses CookieYes to show a cookie banner and remember your choices.

  • Essential cookies — needed to deliver the page (including host, content-delivery, or security cookies) and to store your cookie preferences. These do not require consent.
  • Analytics cookies — we may load Google Analytics to measure traffic. In our configuration we do not use analytics to identify you as an individual. Analytics cookies load only after you accept them in the banner.

You can change or withdraw your choice at any time via Cookie Settings in the footer. You may also disable cookies in your browser (some features may break). Turning on Analytics, CookieYes, or a hosted form under the rules above does not, by itself, require a new version of this Policy.


2. Purposes of use

The purposes below apply only to personal information we handle as a business / controller (for example this marketing site, billing contacts we keep for our own records, recruiting, and similar). They do not apply to personal data a customer registers, enters, or uploads into a SaaS tenant. Tenant data is described in the SaaS processor boundary above and, for Global self-serve subscriptions, the DPA.

We use controller-held personal information as needed for the purposes below. If a new purpose arises outside this list, we will obtain consent when required or otherwise publish the purpose as required by law.

(1) Customers and prospects

  1. Product/service information (new features, improvements, case studies)
  2. Seminars and events
  3. Contracting, account changes, renewals, cancellations, and transaction records
  4. Quotes and billing
  5. Thank-you communications after purchase
  6. Product surveys and related prizes (if any)
  7. Maintenance and incident notices
  8. Customer support and inquiry responses
  9. Certification programs, user/developer communities (if offered)
  10. Product improvement analytics
  11. Marketing and support effectiveness measurement

(2) Business partners (including channel partners)

  1. Partner record management
  2. Contracting and operational communications
  3. Invoicing and payments

(3) Security vulnerability / incident reporters

  1. Communications with reporters
  2. Bug bounty participation and payments (if applicable)
  3. Vulnerability research environment programs (if applicable)

(4) Job applicants

  1. Recruiting communications
  2. Selection process
  3. Prior application history checks
  4. Applicant record management

(5) Employees and former employees

  1. HR and payroll
  2. Social insurance and tax compliance

(6) Media and other individuals

  1. Communications
  2. Seminars and events

(7) Common purposes

  1. Legal compliance
  2. Establishing or defending legal rights
  3. Corporate transactions (merger, acquisition, asset sale)

3. Sharing with third parties

This Section 3 describes third-party provision in the sense used under Japan’s APPI: providing personal data to another organization for that organization’s own use. It does not describe processors or subprocessors we engage to handle data on our behalf. Those engagements are Section 4. For AuditnQ subprocessors, the current list is in the Trust Center. We do not repeat that list here.

We do not provide controller-held personal data to third parties without prior consent, except where:

  • Needed for billing/payment processors in connection with fees (for example Stripe)
  • Needed for co-hosted seminars/events (participant data shared with co-hosts)
  • Needed to protect rights, property, or services against Terms violations
  • Required by law
  • Necessary to protect life, body, or property and consent is difficult to obtain
  • Necessary for public health or child welfare and consent is difficult to obtain
  • Necessary to cooperate with government authorities where seeking consent would impede the duty

4. Entrustment (processors and subprocessors)

We may entrust handling of personal data to external providers. We select providers that maintain adequate protection, contract for data protection, and supervise them appropriately.

Customer SaaS data. Where we process personal data on a customer’s SaaS tenant under their instructions, our role and how disclosure requests are handled are described in the opening SaaS processor boundary above. If we further entrust that processing to subprocessors, this Section 4 applies.

Payment processing (for example Stripe) is typically arranged for our own billing relationship; card data should not be uploaded into questionnaire answers or other tenant content.


5. Security measures

We take administrative, technical, and physical measures to prevent leakage, loss, or damage of personal data, including policies, access control, training, facility controls, system protections, and awareness of foreign cloud hosting locations when data may be stored outside Japan.

We maintain an information security management system and have obtained ISO/IEC 27001:2022 certification (registration IS 805180, BSI; scope covering our services). See also our security policy.


6. Access, correction, suspension, and complaints

For personal data we process on behalf of a customer in SaaS (including AuditnQ tenant content), disclosure, correction, and deletion requests are, as stated above, generally directed to that customer.

For retained personal data we handle as a business / controller, you may request disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of third-party provision within the scope of applicable law. Contact us via Section 8. EEA/UK/Swiss/California residents may also use the data-requests form.


7. Changes

We may revise this Policy without prior notice to reflect legal or business changes. The “Last updated” date will change when we do.


8. Contact

Privacy inquiries: use the Contact page, or email [email protected].

Rendering Consulting Inc.
Personal information inquiry desk