ZENIMAX MEDIA ONLINE PRIVACY NOTICE
Updated March 22, 2018
This Privacy Notice (“Notice”) describes how ZeniMax Media Inc. (“ZeniMax,” “we” or “us”) collects, uses and otherwise processes the personal data we collect about our Users (defined below).
1. Scope and Purpose of this Privacy Notice
This Privacy Notice applies to the personal data (or equivalent term under applicable local laws) that ZeniMax collects and processes about customers, purchasers, subscribers, and/or users (each a “ User ”) of our mobile applications, games, websites and other online services (collectively, our “ Services ”), including games published by Bethesda Softworks and ZeniMax Online Studios, and games developed by other ZeniMax studios; more information about our studios is available at http://www.zenimax.com/studios. This Privacy Notice does not apply to any websites, services, products or mobile applications maintained by other companies or organizations to which we may link.
This Privacy Notice is intended to provide our Users with information about how we collect, use, disclose, and otherwise process their personal data, the choices Users have related to our processing of their personal data, and how Users can exercise their access and other rights over their personal data.
By registering for an account with us, providing your information to us through the Services, or otherwise using any of our Services, you understand and acknowledge that ZeniMax may process your personal data in accordance with this Privacy Notice. IF YOU DO NOT WANT THIS PRIVACY NOTICE TO APPLY TO YOU, PLEASE DO NOT USE OR COMMUNICATE WITH US VIA ANY OF OUR SERVICES. If required by applicable law, we will obtain your consent to our collection, use transfer and disclosure of your personal data.
ZeniMax values the importance of your privacy and has received the ESRB Privacy Certification. This Privacy Notice and the ESRB certification seals shown on our Services confirm that ZeniMax is a valid licensee, and participating member, of the Entertainment Software Rating Board's Privacy Certified Program (“ ESRB Privacy Certified ”). All Services where this Privacy Notice is posted have been reviewed and certified by ESRB Privacy Certified to meet established online information collection, use and disclosure practices. As a licensee of this privacy program, we are subject to audits of our Services and other enforcement and accountability mechanisms administered independently by ESRB Privacy Certified.
2. The Personal Data We Collect
ZeniMax collects personal data directly from Users, automatically via their use of the Services, and in some cases from third parties. The personal data that ZeniMax collects about Users (which may be combined across Services and features) varies depending upon the particular Services used, and may involve the following:
A. Registration and Profile Information. To access and use certain Services (e.g., to register a game, download or use a mobile application, access subscription-based Services, create an account) you must register with us, by providing us with certain required information, which is identified on the registration page. Depending upon the Service, this may include your name, a user name and password, as well as country of residence, email, and contact information; certain Services will not be available if you decline to provide required information. We may also ask you or allow you to submit certain optional information, which may include your phone number, birthdate, location, preferences, a photo or avatar, and other profile information.
B. Information from Third Party Accounts. You may be able to connect certain third-party accounts
(each a “ Third Party Account ”) – such as Steam, Twitch, Xbox Live, PSN and Facebook – to your account with us, so that you can connect with your friends and network, share game information, and in some cases make purchases and redeem or earn points and rewards (subject to applicable program terms). In addition to linking a Third Party Account, we also may allow you to login to certain Services through certain third party accounts, including Steam ( See http://store.steampowered.com/privacy_agreement/) and Facebook http://www.facebook.com/about/privacy/ (each a “ Third Party Account ”). If you choose to login this way, you are asked to share certain information with us (which may include name, email, friends and public profile information); the specific information and whether it is required or optional is stated on the permissions page when you login with the Third Party Account.
C. Subscriptions, Purchases and Payments Information. If you make a purchase or sign up for certain subscription-based Services, you are required to provide your payment information, including name, billing and shipping address and details, payment type, as well as credit card number or other payment account details (e.g., PayPal). We work with third parties like payment processors and fulfillment partners to process these payments. We do not collect, receive, process or store credit card or debit card numbers, or other third-party payment account credentials (e.g., PayPal); this information is collected directly by these third parties. Depending upon the Service, we may receive your username, name, email, the payment type, product(s) or service(s), and other transaction details, and maintain records of your purchase and subscription history.
D. User / Device Identifiers. When you access, play or use our Services, we may collect IP address, MAC address, console identifiers (e.g., XUID and PUID), and other device identifiers; we also assign account holders a unique user identifier, which we use to identify and link relevant information to your User account (e.g., in-game information such as statistics, scores, achievements and subscription levels).
E. Subscribing to Emails, and Participating in Sweepstakes, Contests, Surveys and Similar Activities. Users can sign up online or in-person (e.g., at tradeshows, conferences and the like) to receive direct marketing communications from us, including emails about game launches, developments, and upcoming releases. If you agree to receive direct marketing communications from us, we collect your email address, and we may also collect your name, preferences, and, if relevant, information about your account and the Services and other games you use. We may also run contests, sweepstakes or other events or activities (collectively, “events”) on our websites and social media channels. Information collected for these events may include your name, age, email address, and other information.
F. Your Communications When you email us, call us, or otherwise send us communications regarding the Services, we collect and maintain a record of your contact details, communications and our responses. We may also maintain records of the in-game communications and information that you post in chat sessions, forums, and in other areas of the Services.
G. Your Activities, Stats, Friends and Preferences. We collect usage and preference details related to your use of the Services, such as language, in-game purchases, game-play statistics, scores, persona, characters, achievements, rankings, time spent playing, click paths, game profile, preferences, friends (including friend relationships through, for example, the creation of clans) and other data that you provide to us as part of your account.
I. Guest Player Information. Some of our games may allow you to play without creating an account and/or registering with us. In such cases, we may assign you a guest user ID so that we can keep track of your game play, scores, stats, purchasing data and usage data for your current and future sessions. If you later decide to register or create an account with us, we may associate your guest ID and the data from your guest session(s) with your account.
J. Information from Third Party Sites. We also may use third party tools to help us manage and analyze our social media presence, and report on comments, mentions and other content that is posted about us on social media sites and other public channels and forums. These third parties’ activities, and their information collection and sharing practices, are subject to the terms of the relevant social media site, channel or forum. We will use this information in accordance with this Policy.
Children. ZeniMax does not knowingly request or collect personal data from children younger than 13 years of age. If you believe that we may have unintentionally collected personal data from a child under 13, contact us as set forth at the bottom of this Privacy Notice, and we will take action as necessary to securely delete such information.
Unless otherwise specified above, generally we collect your personal data on a voluntary basis. However, as noted above, if you decline to provide certain personal data that is marked mandatory, you may not be able to access certain Services and we may be unable to fully respond to your inquiry.
3. How We Use Personal Data
Generally, we may use the personal data we collect from you for the purposes and lawful bases described below:
For the performance of our agreement with you. The personal data referred to under Section 2. A, B, C, D, E, F, G and I above may be used to provide our Services to you, including to run contests, sweepstakes or other events or activities in which you participate; improve your gameplay experience; provide tailored customer services and support; matching; for billing and payment purposes; and to handle your enquiries.
To comply with a legal obligation to which ZeniMax is subject. Any personal data referred to above, especially the personal data under Section 2. C above may be used to maintain appropriate business records; comply with lawful requests by public, governmental and other regulatory authorities or the courts in any relevant jurisdiction; and to comply with applicable laws and regulations; or as otherwise required by law.
For our legitimate commercial interests. The personal data referred to under Section 2. D, E, F, G, H and I above may be used to improve and develop our products and services; analyse the use of our Services and generate aggregate statistics about our User community; personalize your experiences (e.g., for your geographic area); send or display targeted marketing; facilitate software updates; assist in security and fraud prevention; for system integrity (preventing hacking, cheats, spamming, etc.); facilitate our business operations and maintain appropriate business records; operate company policies and procedures; facilitate our response to legal process (e.g., a court order, warrant or subpoena); enable us to merge, sell, acquire, or transfer assets; and for other legitimate business purposes permitted by applicable law.
Use of information based on your consent. We may use personal data about you based on your express consent, for example to send you marketing communications, surveys, news, updates and other communications. Users may be able to withdraw their consent at any time in accordance with applicable laws; please see the Marketing and Communications Choices and the Access, Amendment, and Other User Rights sections below for information on how to withdraw your consent.
In addition to marketing purposes, where required by applicable law, ZeniMax will obtain your consent to this Privacy Notice and our collection, use and disclosure of your personal data.
4. How ZeniMax Shares Personal Data
ZeniMax may disclose your personal data as follows, and we will obtain your consent to do so where required by applicable law:
Service Providers and Processor. We may engage vendors, agents, service providers, and affiliated entities to provide services to us or to Users on our behalf, such as support for the internal operations of our websites, online stores (including payment processors), products (such as our games) and services (e.g., message board operations, and technical support processing), as well as related offline product support services, data storage and other services. In providing their services, they may access, receive, maintain or otherwise process personal data on our behalf. Our contracts with these service providers do not permit use of your personal data for their own marketing and other purposes.
ZeniMax Group Companies. ZeniMax may also share personal data about you with our subsidiary or affiliate companies (see http://www.zenimax.com/legal_information) for purposes of assisting us to market our Services and games, analytics, research and demographic studies, development, and to help us improve and tailor the Services we provide. If you have consented, we may also share your personal data so that they may contact you about other products and services offered by ZeniMax affiliates as set forth in the Marketing and Communications Choices section below. Our subsidiary or affiliate companies are subject to this Privacy Notice when they use your personal data.
Legally Required. We may also disclose your personal data if we believe we are required to do so by law, or that doing so is reasonably necessary to comply with legal processes; when we believe necessary or appropriate to disclose personal data to law enforcement or other governmental or regulatory authorities or the courts (in any relevant jurisdiction worldwide), such as to investigate actual or suspected fraud or violations of law, breaches of security, or breaches of this Privacy Notice; to respond to any claims against us; and, to protect the rights, property, or personal safety of ZeniMax, our customers, or the public.
Corporate Transaction. In addition, your personal data may be disclosed as part of any proposed or actual merger, sale, and transfer of ZeniMax assets, acquisition, bankruptcy, or similar event.
With Consent. We may also disclose your personal data to any other affiliated or third parties where you have consented or requested that we do so. For example, if you win a contest or sweepstake, we may disclose the names of winners online, and we may also share your information with third party partners and co-sponsors, where relevant; in such cases, we will clearly notify you of the sharing, and you will have the choice not to participate or to otherwise object to such sharing. Where required by applicable law, we will publish information online or in the local press and to relevant regulators identifying the winner(s) of a context or sweepstake regardless of whether or not you consent to the same.
Notwithstanding anything else in this Privacy Notice, we may share aggregate or de-identified information with third parties for research, marketing, analytics and other purposes, provided such information does not identify a particular individual and the individual cannot be re-identified.
5. Cookies, Analytics and Personalization
protect our Services, as well as for targeted marketing and advertising, to personalize content and for analytics purposes (see the “ Access, Amendment, and Other User Rights” section below for information about opting-in out of certain uses of your personal data)
- Log Files. We collect certain activity information from log files. Log file information is automatically reported by your browser or mobile application to our servers when you access our Services. We record certain information from these log files, including web requests, IP address, browser type and version, language information, referring and exiting URLs, links clicked, pages viewed and other similar information.
- Cookies. Are small files with a unique identifier that are transferred to your browser through our websites. They allow us to remember Users who are logged in, to understand how Users navigate through and use our Services, to display personalized content and targeted ads (including on third party sites and applications).
- Clear GIFs, pixel tags and web beacons. These are tiny graphics with a unique identifier, similar in function to cookies that we use to track the online movements of Users of our Services and to personalize content. We also use these in our emails to let us know when they have been opened or forwarded, so we can gauge the effectiveness of our communications.
- Anti-Cheat and Fraud Prevention Technologies. We use “anti-cheating” and fraud prevention tools or applications, which may collect information about your browser, device and activities within the Services, to detect and prevent fraud and cheating.
6. Third Party Advertising
Custom Audiences and Matching. Unless you have opted out, we may share certain information (such as your email address) with third parties – such as Facebook and Google – so that we can better target ads and content to our Users, and others with similar interests, within their services. These third parties use the personal data we provide to help us target ads and to enforce their terms, but we do not permit them to use or share this data with other third-party advertisers. You can opt-out of our sharing your personal information to target you this way by emailing us at [email protected]. If you opt out, we will process your opt out in a reasonable amount of time.
As noted above, you may control how Google, Facebook and other third parties display certain ads to you, as explained further in their respective privacy policies and ad preferences pages. You can also obtain more information about targeted advertising, and how to opt-out of receiving targeted ads from many third-party ad networks (including Facebook and Google), through the following:
For U.S. Users:
- http://www.networkadvertising.org/optout_nonppii.asp (Network Advertising Initiative)
- http://www.aboutads.info/choices (Digital Advertising Alliance)
For Users in the EU: http://www.youronlinechoices.eu (European Interactive Digital Advertising Alliance)
For Users in Canada: http://youradchoices.ca/choices/ (Digital Advertising Alliance of Canada)
Opting out of participating ad networks does not opt you out of being served advertising. You may continue to receive generic or “contextual” ads on our Services. You may also continue to receive targeted ads on other websites, from companies that do not participate in the above programs.
7. Do-Not-Track Requests
8. Third Party and/or Social Features
Our Services may include or incorporate social media and other third-party features (e.g., widgets, buttons, and plugins), which are operated by third party platforms and networks such Facebook, Steam, Twitch, Twitter, Instagram, YouTube, and others. These features are hosted by the respective third-party operator even though they appear on our Services, and the third party may collect your IP address, URL, date and time stamp, browser details and the like, subject to their own privacy policies.
9. Marketing and Communications Choices
As noted, if you agree we may send direct marketing communications to you about our Services, events and promotions, and we may also send you surveys, news, updates and other communications via email. If you wish to stop receiving direct marketing and these other communications from us, you may change your account settings to opt out as set forth below in the Access, Amendment, and Other User Rights section below. If you opt out of direct marketing communications, we may to the extent permitted by applicable law still send you non-promotional communications, such as those about your account or our ongoing business relations. For example, if our service is temporarily suspended for maintenance, we might send you an email. Generally, you may not opt-out of these communications, which are not promotional in nature. If you do not wish to receive them, you have the option to deactivate your account.
In some of our mobile Services, with your consent, we may send push notifications from time-to-time in order to update you about the game, events or promotions that we may be running. If you no longer wish to receive these types of communications, you may turn them off at the device level.
10. Security of Your Information
The security of your personal data is important to us. ZeniMax takes steps to protect against possible breaches of our Services and the personal data we maintain. However, no website or Internet transmission is completely secure. Thus, ZeniMax cannot and does not guarantee that unauthorized access, hacking, data loss, or other breaches will never occur. We urge you to take steps to keep your personal data safe, such as choosing a strong password and keeping it private, as well as logging out of your User account, and closing your web browser when finished using the Services.
11. Data Retention
We will retain your personal data as long as necessary for purposes for which the personal data was collected and is used by us, as stated in this Privacy Notice. If you wish to cancel your account or request that we no longer use your personal data to provide the Services to you please contact us as set forth in the Access, Amendment, and Other User Rights section below. However, if you withdraw consent or otherwise object to our collection, use and disclosure of your personal data, you may not be able to use the Services. Further, to the extent permitted by applicable law, we will retain and use your personal data as necessary to comply with our legal obligations, resolve disputes, maintain appropriate business records, and enforce our agreements.
12. International Transfers of Data
ZeniMax is headquartered in the United States, and has operations, entities and service providers in the United States and throughout the world. As such, we and our service providers may transfer your personal data to, or access it in, jurisdictions (including the United States and other jurisdictions where we, our affiliates and service providers have operations) that do not provide equivalent levels of data protection as your home jurisdiction. We will take steps to ensure that your personal data receives an adequate level of protection in the jurisdictions in which we process it, including through appropriate written data processing terms and/or data transfer agreements.
Users in the European Economic Area (EEA): Your personal data may be transferred to and processed in the United States and other jurisdictions that do not provide equivalent levels of data protection according to the European Commission. In such cases, ZeniMax will take steps to ensure that appropriate safeguards are in place to protect your personal data, including by putting in place standard contractual clauses as approved by the European Commission (the form for the standard contractual clauses can be found at http://ec.europa.eu/justice/data-protection/international-transfers/transfer/index_en.htm).
13. Third Party Links
Our websites may contain links to third party sites that are not owned or controlled by ZeniMax. We are not responsible for the collection and use of your information by these third-party sites. We recommend that you read the privacy notice of the website to which you link before you submit any personal data.
14. User Generated Content
You may choose to disclose information (including personal data) about yourself in the course of contributing user generated content to ZeniMax Services such as forums. Information that you disclose in any of these forums is unencrypted public information, and may be accessed by members of the public, who are not subject to this Privacy Notice. In addition, when you enter certain public
areas of our Services, your username and other public profile information may be viewable by others. You should have no expectation of privacy as to any information you post or display in our forums or games, or in your profile, or that you otherwise make available on our or through our Services.
15. Access, Amendment, and Other User Rights
ZeniMax gives Users several easy-to-use ways to access, amend and exercise their choices and rights regarding their personal data. In addition, Users may also have the right to request that certain personal data be exported to another provider where technically feasible, and, under certain conditions to object to or restrict our use of certain personal data.
Marketing Preferences. You may change your email preferences and opt out of marketing communications through your profile settings.
Access, Amendment and Other Rights. If you have registered with us and wish to access or update your profile, or exercise certain opt out rights, you may do so online by visiting the “profile” settings in your account. You may also contact our Privacy Coordinator as set forth below to access or amend your personal data, to request that we delete or stop processing your personal data, to withdraw your consent to our processing, and, if you are an EEA resident, to exercise your opt-out rights or place a data portability request.
Remove Content. If you wish to request removal of any content you have posted, you should also contact our Privacy Coordinator as set forth below.
Privacy requests should be directed to the ZeniMax Media Inc. Privacy Coordinator at [email protected], or 1370 Piccard Drive, Rockville, MD 20850 USA. Please keep in mind that certain Services will not be available if you withdraw your consent, or otherwise delete or object to our processing of certain personal data. We will respond to your request in accordance with applicable law, and we will inform you if we do not intend to comply with your request.
You also have the right to lodge a complaint with a supervisory data protection authority.
16. Your California Privacy Rights
We do not share personal data collected online with unaffiliated third parties for their own direct marketing purposes and will not do so unless you agree to such disclosure. If you are a California resident and you still believe your information has been shared or you have general questions about how your information may have been shared, you may contact us by requesting a list of the third parties to which we have disclosed personally identifiable information about you for their own direct marketing purposes. You may make one request per year. In your request, please attest to the fact that you are a California resident and provide a current California address for your response. You may request this information in writing by contacting us at via email at [email protected] or by regular mail at: Privacy Coordinator, ZeniMax Media Inc., 1370 Piccard Drive, Rockville, MD 20850 USA. Please allow up to thirty (30) days for a response.
17. Contact Details
The controller for your personal information is ZeniMax Media Inc.,1370 Piccard Drive Rockville, MD 20850 USA. In addition, for purchases made by Users in the EEA, ZeniMax Europe Ltd., Reg. No. 06333300, Haymarket House, 29-29 Haymarket, London SW1Y 4SP, is a joint- controller for your transaction data. This privacy notice applies to both ZeniMax Media Inc. and ZeniMax Europe Ltd., and data subjects may exercise their rights with respect to their EEA transaction data with both entities by contacting ZeniMax Media Inc. as set forth below.
If you have any questions, complaints or comments regarding our Privacy Notice or practices, please contact our Privacy Coordinator via email at [email protected] or by regular mail at:
ZeniMax Media Inc.
1370 Piccard Drive
Rockville, MD 20850 USA
As previously mentioned, we are a licensee of ESRB’s Privacy Certified Program. If you believe that we have not responded to your inquiry or your inquiry has not been satisfactorily addressed, please contact ESRB Privacy Certified at http://www.esrb.org/privacy/contact.aspx or:
Attn: VP, Privacy Certified Program
420 Lexington Avenue, Suite 2240
New York, NY 10170 USA
18. Changes to this Privacy Notice
This Policy is current as of the Effective Date set forth above. We may change this Policy from time to time, so please be sure to check back periodically. We will post any changes to this Policy on our Site. If we make any changes to this Policy that materially affect our practices with regard to the personal information we have previously collected from you, we will endeavor to provide you with notice in advance of such change by highlighting the change on our Site and giving you additional choices regarding such change prior to the material change becoming effective.