View U.S. Privacy Notice View Japan Privacy Notice View South Korean Privacy Notice
Hi. We’re Square Enix. You probably know us from our games like FINAL FANTASY, DRAGON QUEST, and SPACE INVADERS. Please take some time to read this Privacy Notice because it explains how we collect, use, and protect your personal information (PI).
From the moment you start interacting with us, we begin collecting your PI. Sometimes you give us this PI, and sometimes we collect it automatically.
Depending on how you interact with us, we collect different types of PI:
Game Platforms:
Mobile Platforms and App Stores:
When you log in with your social media account:
When you link a Square Enix account to a Game Platform Account:
We only use your PI for specific reasons. The reasons depend on how you interact with us. Our reasons and lawful bases, as described below, depend on how you interact with us. For example, we only process payments if you make or try to make a purchase.
Registering your account: When you sign up for our services or create a Square Enix account, we use the details you provide us to process your registration and provide the services you agreed to receive.
In the EU and UK, our lawful basis for this use of your PI is: contract.
Keeping our services running: Provide you our games and services online, access to our websites and keeping it all secure.
In the EU and UK, our lawful basis for this use of your PI is: contract.
Optimising our services for you: Remembering your settings, analysing your use of our services and creating leaderboards.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Verifying your age: We use your information to verify your age and provide you an age-appropriate experience.
In the EU and UK, our lawful basis for this use of your PI is: legal obligation.
Communicating with other players: To enable you to communicate and interact with other users on our websites and online services.
In the EU and UK, our lawful basis for this use of your PI is: contract.
Processing Orders: We use your information to process, accept, dispatch and deliver your orders.
In the EU and UK, our lawful basis for this use of your PI is: contract.
Processing payments: We use your information to process payments for our goods and services. If your bank provides account update services, we may automatically update your payment card information when it changes.
In the EU and UK, our lawful basis for this use of your PI is: contract.
Anti-cheat, anti-tampering and unauthorised activity prevention and detection: We use your information to enforce our rules and policies, protect our customers and business, and investigate and respond to unauthorised activity on or related to our games or services. We may also use your information for machine learning behavioural predictions to detect and prevent unauthorised activities on our games or services.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Fraud and unlawful activity detection, prevention and investigation: We use your information to investigate and respond to fraudulent or illegal activity on or related to our games and services. We may also use your information for machine learning behavioural predictions to detect and prevent fraudulent activities on our services.
In the EU and UK, our lawful basis for this use of your PI is: legal obligation.
Square Enix “Press Hub” registration: We use your information to process your application and send you press releases and assets.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Square Enix “influencer” registration and suitability monitoring: We use your information to process your application and to contact you about participation in the program.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Community and customer support: We use your information for handling enquiries or complaints, troubleshooting and solving technical issues over live chat, phone, email and in-game chat.
In the EU and UK, our lawful basis for this use of your PI is: contract.
Social media: We use your information to communicate and interact with you on social media and to understand customer sentiment about our games and services.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Keeping our products and services up to date: We use your information to make necessary changes to our products and services and to monitor your participation in our forums and services.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Improving and developing our games, services and websites: We use your information collected through our games, services and websites for analytics, research and website traffic optimisation.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Recruitment: We use the information you provide us during our recruitment process to evaluate your suitability for the role, verify your details, identify future employment opportunities and to optimise the recruitment process.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Contests and prize draws: We use your information to process your entry, communicate with you and award and send you prizes either digitally or physically. Some contests and prize draws will also involve publicly displaying your entry in leaderboards or media.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Tournament participation: We use your information to enable you to enter and participate in tournaments, communicate with you, and award and send you prizes either digitally or physically. Some tournaments will also involve publicly displaying and promoting your entry in leaderboards and in media.
In the EU and UK, our lawful basis for this use of your PI is: contract.
Live Square Enix Events: We may photograph or record videos that include you at our live events.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Targeted advertising: Where you have consented to it, we use cookies and similar technologies to deliver relevant ads and offers to you and measure their effectiveness. Please also see our Cookie Notice.
In the EU and UK, our lawful basis for this use of your PI is: consent.
Social media retargeting ads: We use your information to display ads to you on social media about our games and services that are of interest to you and players like you, and to analyse their effectiveness.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Digital marketing: We match your information collected from our websites, games, and services to profile your interests and behaviours and segment your information with other players who have similar interests for tailored marketing and analysis. We also use your information for machine learning and AI to predict the effectiveness of our marketing and ad campaigns for you and players like you, including through purchase history and game play behavioural analysis.
In the EU and UK, our lawful basis for this use of your PI is: legitimate interest.
Direct marketing: Where you have consented, we will use your information to send you communications about our services, products and features that you have agreed to receive directly via email.
In the EU and UK, our lawful basis for this use of your PI is: consent.
Health Apps: Some of our mobile games have the ability to make use of your device‘s ‘health app’ (Apple HealthKit for Apple devices, Google Fit for Android devices, or its equivalent) in order to process your fitness activity in the game.
Where you have chosen to connect your device’s health app to one of our games, we use the data obtained from your device's health app only for the purpose of providing health management, movement, or exercise services in connection with the specific game. We do not use data collected through your device's health app for marketing or advertising purposes and our use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
We will only collect the health data you give us permission to collect and you will always be in control of this data collection; we cannot use your device's health app without your specific consent and you can withdraw consent to this data collection at any time in your device’s health app settings.
In the EU and UK, our lawful basis for this use of your PI is: consent.
Consent: You have provided clear and unambiguous consent for us to process your PI for a specific purpose. You have the right to withdraw this consent at any time.
Contract: We need to process your PI for us to fulfil our contractual relationship with you.
Legitimate interests: We need to process your PI for our legitimate interests, or the legitimate interests of a third party, in conducting and managing our business and our relationship with you. When we use your PI for our legitimate interests, we take into account any potential impact that such use may have on you.
Legal obligation: We have a legal obligation under applicable law to process your PI.
We protect your PI using physical, technical, and administrative safeguards.
If you believe your PI has been breached, please contact us immediately at DPO@eu.square-enix.com.
We secure access to all transactional areas of our websites and apps, restrict access to your PI, secure and tokenise transactional information and regularly monitor our systems for possible vulnerabilities and attacks.
We may share your information with third party companies that carry out work on our behalf. These companies only use your information for the services they provide for us, and they must delete it when they stop working for us:
Third-party IT companies who support our websites, online services and other business systems, as well as payment services providers who process your payments.
Fraud detection, investigation and prevention companies that help us detect, investigate and prevent cheating, abuse, fraud, tampering or other unauthorised use of or disclosure of non-public information about our current and future services.
Direct marketing companies that assist us in managing our electronic communications with you.
Selected third-party warehouses and distribution partners to deliver orders you have made with us.
With your consent or based on our legitimate interests - Google, Facebook and other third-party advertising partners so they can show you our products and services that might be of interest to you.
Under very specific circumstances, we will disclose your PI with third parties (including law enforcement bodies) in order to respond to or investigate fraudulent, unauthorised or criminal (or potentially fraudulent, unauthorised or criminal) activity on or related to our systems, services, or events, including the unauthorised disclosure of non-public information related to current or future services.
We may also be required by law to disclose your PI to the police or to another law enforcement, regulatory or government body in your country of origin or elsewhere, including upon receiving a legally valid request to do so. We may also be required by law to disclose your PI to third parties in response to a court order, subpoena, or other compulsory process.
We use cookies and similar tracking tools for analytics, improving your experience, and showing you ads. Please see our Cookie Notice for more information.
We are a global organisation. So we sometimes need to share your information with our other offices, or with third parties located in other countries.
When it is necessary for us to transfer your personal data out of your location, for example the EEA and/or the UK, we will do so only when the transfer is authorised under applicable law, including when the transfer is made to a country the EEA and/or UK has deemed to have adequate data protection laws, is governed by the Standard Contractual Clauses and/or the U.K. Addendum or is authorised by another recognised transfer mechanism recognised by the EEA, Swiss, or UK authorities, such as the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
Square Enix complies with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF as set forth by the U.S. Department of Commerce. Square Enix, Inc has certified to the U.S. Department of Commerce that it and its U.S. entities adhere to the EU-U.S. DPF Principles with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Square Enix, Inc. has certified to the U.S. Department of Commerce that it and its U.S. entities adhere to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the DPF program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
Square Enix, Inc. is responsible for the processing of personal data it receives under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, and subsequently transfers to a third party acting as an agent on its behalf. Square Enix complies with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF Principles for all onward transfers of personal data from the EU, UK, and Switzerland, including the onward transfer liability provisions. Square Enix shall remain liable if third parties process your data in a manner inconsistent with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, in accordance with the onward transfer liability provisions.
Square Enix, Inc. is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC). The FTC has jurisdiction over Square Enix, Inc.’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. In certain situations, Square Enix may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Square Enix commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF to JAMS, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit the U.S.-based third-party dispute resolution provider for more information or to file a complaint. The services of JAMS are provided at no cost to you.
Under certain conditions, more fully described on the Data Privacy Framework website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework, Square Enix commits to resolve complaints about your privacy and our collection or use of your personal information transferred to the United States pursuant to the DPF Principles. European Union, Swiss, and United Kingdom individuals with DPF inquiries or complaints should first contact Square Enix, Attn: Privacy Team and DPO, Square Enix 240 Blackfriars Road SE1 8NW or by email at dpo@eu.square-enix.com.
We only keep your PI as long as necessary for providing our services. Once it’s no longer needed, we delete or anonymise it.
We will retain your PI for only as long as you are a customer or are using our services and for no longer than is necessary after that. We will securely destroy or irreversibly anonymise your PI once it is no longer necessary for us to retain it.
You have the following rights under data protection and privacy laws:
To exercise any of these rights, you can use our dedicated Rights Request Portal or email us at DSAR@eu.square-enix.com.
Customers in the EU or UK may also lodge a complaint regarding our use of your PI. If you have such a complaint, we ask that you please tell us first so we can have a chance to look into your concerns. If you remain unsatisfied, you can contact your local Supervisory Authority or the Information Commissioner’s Office on their website at www.ico.org.uk.
If you have any questions about your PI, please contact our data protection officer at DPO@eu.square-enix.com.
This Privacy Notice may change over time. We will inform you of any major updates.
You made it to the end! Thank you for your dedication to understanding your rights and how we handle your PI. If you have any questions about this notice, please contact our DPO: DPO@eu.square-enix.com
Choose a date below to view a previously published version of this document