SBTM Personal Information Processing Policy

SBTM Co., Ltd. (hereinafter referred to as the "Company") provides a business trip management reservation experience that enhances customer convenience and saves time through real-time reservations for flights, hotels, and rental cars for business trips. To protect the freedom and rights of data subjects, the Company complies with the Personal Information Protection Act and related laws and regulations, lawfully processing and safely managing personal information. Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Company establishes and discloses the following personal information processing policy to inform data subjects of the procedures and standards for processing and protecting personal information and to promptly and smoothly address any complaints related to this matter.

일반 개인정보 수집
General Privacy Collection
Name, Phone, E-mail etc
※ Check the personal information processing policy for details
고유식별정보 수집
Collecting unique identification information
Passport Number
개인정보 처리 목적
Purpose of Personal Information Processing
Member management, Business trip reservation etc
※ Check the personal information processing policy for details
개인정보 보유기간
Personal information retention period
Membership & business travel reservation data: Deleted upon membership withdrawal request or contract termination after settlement completion
(If no login or reservation history, stored separately for 1 year then deleted upon withdrawal)
※ Retained if required by applicable laws
개인정보 파기
Delete personal information
Collection and use of personal information
Delete when achieving the purpose
※ Check the personal information processing policy for details
개인정보 제공·위탁
Entrustment of personal information provision
[Personal Information Provision]
Jin Air, The Shilla,
Samsung Fire & Marine Insurance, etc.
[Personal Information Entrustment] Hotel Shilla, First Trip, KG Inicis, etc.
※ for detail information, plase refer to the privacy policy.
개인정보 국외이전
Transfer of personal information abroad
Samsung Hospitality America Inc, Samsung Hospitality U.K inc etc
※ Check the personal information processing policy for details
고충사항 처리부서
Complaint Handling Department

[Manager of Personal Information Protection ]

  • -affiliation: SBTM
  • Contact: 02-6048-8603
  • e-mail: sbtm.security@.samsung.com
1. 개인정보의 처리목적, 처리 항목, 보유 및 이용 기간 1. Purpose of Personal Information Processing, Processed Items, Retention and Usage Period

① The company collects the minimum necessary information from the data subject to provide "business trip reservation" services for airlines, hotels, and rental cars. The company processes the following personal information with the consent of the data subject in accordance with Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act.

Basis for Collection Category Purpose of Collection and Use Items Collected Retention and Use Period Service Target
Personal Information Protection Act
Article 15, Paragraph 1, Subparagraph 1
(Information Subject's Consent)
Membership registration SBTM (Hotel Shilla subsidiary) product and gift/promotional event information Shilla Duty Free (operated by Hotel Shilla) product and gift/promotional event information [Optional] Name, phone number, e-mail Destroyed upon membership withdrawal or consent withdrawal Republic of Korea
Identity verification, service provision, Complaint Processing [Optional] Employee Number, Landline Deleted after
membership withdrawal
request/contract termination
and settlement completion
or consent withdrawal
Korea, Americas, Europe, Southeast Asia, Southwest Asia, China
Personal Information Protection Act
Article 24, Paragraph 1, Subparagraph 1
(Unique Identification Information)
Flight Reservation Flight Reservation Passport information (passport number, passport expiry date) Deleted after
membership withdrawal
request/contract termination
and settlement completion
Korea, Americas, Europe, Southeast Asia, Southwest Asia, China
Personal Information Protection Act
Article 15, Paragraph 1, Subparagraph 1
(Consent of the Data Subject)
Business Trip Reservation Flight/Hotel/Rental Car Mileage Accumulation [Optional] Membership Information (Membership Number) Deleted after
membership withdrawal
request/contract termination
and settlement completion
or consent withdrawal
Korea, Americas, Europe, Southeast Asia, Southwest Asia, China
TSA Information [Optional] Known Traveler Number, Global Entry Number Deleted after
membership withdrawal
request/contract termination
and settlement completion
or consent withdrawal
South Korea, Americas, Europe, Southeast Asia, Southwest Asia, China
Personal Information Protection Act
Article 15, Paragraph 1, Subparagraph 1
(Consent of the Data Subject)
Visa Application Visa Information Name, English Name, Date of Birth, Gender, Mobile Phone Number Deleted after
membership withdrawal
request or
contract termination
and settlement completion
Korea, Americas, Europe, Southeast Asia, Southwest Asia, China
Personal Information Protection Act
Article 24, Paragraph 1, Subparagraph 1
(Unique Identification Information)
Passport Information Passport Number, Passport Expiration Date Deleted after
membership withdrawal
request or
contract termination
and settlement completion
Korea, Americas, Europe, Southeast Asia, Southwest Asia, China


② The company processes the following personal information items without the consent of the data subject in accordance with Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act.

Basis for Collection Classification Purpose of Collection and Use Items Collected Retention and Use Period Service Target
Personal Information Protection Act
Article 15, Paragraph 1, Subparagraph 4
(Contract Conclusion and (Implementation)
Membership Registration Identity Verification for User Identification ID, password, company name, branch office, department, position, name (Korean/English), date of birth, nationality, email, mobile phone, gender Deleted after
membership withdrawal
request or
contract termination
and settlement completion
Korea, Americas, Europe, Southeast Asia, Southwest Asia, China
Personal Information Protection Act
Article 15, Paragraph 1, Subparagraph 4
(Contract Conclusion and (Implementation)
Business trip reservation Flight ticket reservation/issuance/change and cancellation Information collected through "Membership Registration" and credit card number, credit card expiration date Deleted after
membership withdrawal
request or
contract termination
and settlement completion
Korea, Americas, Europe, Southeast Asia, Southwest Asia, China
Hotel reservation/change and cancellation Information collected through "Membership Registration" and credit card number, credit card expiration date Deleted after
membership withdrawal
request or
contract termination
and settlement completion
Korea, Americas, Europe, Southeast Asia, Southwest Asia, China
Car rental reservation/change and cancellation "Information collected through membership registration" Deleted after
membership withdrawal
request or
contract termination
and settlement completion
Korea, Americas, Europe, Southeast Asia, Southwest Asia, China
PICKUP SENDING reservation/change and cancellation "Information collected through membership registration" Deleted after
membership withdrawal
request or
contract termination
and settlement completion
Southeast Asia

③ When the company collects personal information from the information subject, Upon expiration of the consented personal information retention period or upon membership withdrawal, personal information collected with the consent of the information subject for the purposes of "membership registration" and "business trip reservation" is promptly destroyed.
Personal information consented to upon membership registration is stored separately for one year if there is no access or reservation history and then destroyed upon membership withdrawal.
However, even after the purpose of collection or use of personal information has been achieved, if it is necessary to preserve it in accordance with relevant laws and regulations, the information subject's personal information may be retained.
- 「Act on Consumer Protection in Electronic Commerce, etc.」 Records of consumer complaints or dispute resolution: 3 years
- 「Act on Consumer Protection in Electronic Commerce, etc.」 Records of legal contracts or contract cancellations: 5 years
- 「Act on Consumer Protection in Electronic Commerce, etc.」 Records of payment and supply of goods: 5 years
- 「Protection of Communications Secrets Act」 Website visit records: 3 months

2. 개인정보의 파기 절차 및 파기방법 2. Personal information destruction procedures and Destruction Method

① When personal information becomes unnecessary due to the expiration of the retention period or the achievement of the processing purpose, the Company will destroy the relevant personal information without delay.

② If the retention period for personal information agreed upon by the data subject has expired or the processing purpose has been achieved, but the personal information must be retained in accordance with the laws of the country where the data subject resides, the personal information will be stored separately from other personal information for the relevant period. Separately stored personal information will not be used for any purpose other than the storage purpose unless requested by the data subject or required by other laws.

③ The procedures and methods for destroying personal information are as follows:

1. Destruction Procedure
The Company selects personal information for which reasons for destruction have arisen and destroys the personal information with the approval of the Company's Personal Information Protection Officer.

2. Destruction Method
The Company will store the personal information in electronic file format. Recorded and stored personal information is destroyed so that it cannot be restored. Personal information recorded and stored on paper documents is shredded or incinerated.

4. 개인정보의 제공 3. Matters Concerning the Provision of Personal Information to Third Parties

① The company does not use or provide personal information beyond the scope notified in "Purpose, Items, Retention & Use Period of Personal Information Processing" unless consent is obtained or required by law.

② Except when there is a risk of unfairly infringing on the interests of the data subject or a third party, the Company may provide personal information in the following cases:


- When separate consent has been obtained from the data subject

- When there are special provisions in the law or when it is unavoidable to comply with legal obligations

- When it is clearly deemed necessary to protect the urgent life, body, or property interests of the data subject or a third party

- When necessary to achieve the company's legitimate interests and when such interests clearly take precedence over the rights of the data subject. In this case, this applies only to cases where it is significantly related to the company's legitimate interests and does not exceed a reasonable scope.

- When urgently necessary for public safety and well-being, such as public health.


③ The company provides the following personal information items only to the minimum extent necessary with the consent of the data subject in accordance with Article 17(1)1 or Article 24(1)1 of the Personal Information Protection Act.

division recipient Purpose of Provision Personal information items provided Retention period Service target
aviation List (pop-up) Book flight tickets and check availability for departure Name (Korean), English name on passport, date of birth, gender, email, credit card number, credit card expiration date, Passport number, passport number expiration date, passport nationality If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. korea
Airline Mileage Accumulation Membership Information (Membership Card Number) If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. korea
US Airlines Domestic Flight Identification (TSA) Known Traveler Number, Global Entry Number If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. Korea, America, Europe, Southeast Asia, Southwest Asia, China
hotel List (pop-up) Process/confirm hotel reservation Name (Korean), English name on passport, date of birth, gender, email, credit card number, credit card expiration date, Passport number, passport number expiration date, passport nationality If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. korea
Hotel Mileage Accumulation Membership Information (Membership Card Number) If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. korea
rental car List (pop-up) Car rental reservation process/confirmation Name (Korean), English name on passport, date of birth, gender, email, credit card number, credit card expiration date, Passport number, passport number expiration date, passport nationality If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. korea
Rental Car Mileage Accumulation Membership Information (Membership Card Number) If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. korea
GDS List (pop-up) Hotel/flight reservations Name (Korean), passport English name, date of birth, gender, email, credit card number, credit card expiration date, membership number, passport number, passport number expiration date, passport nationality If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. Korea, America, Europe, Southeast Asia, Southwest Asia, China
List (pop-up) Rental car reservation Passport English name, date of birth, gender, email, membership number If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. Korea, America, Europe, Southeast Asia, Southwest Asia, China
Aggregator List (pop-up) Flight and hotel reservations Name (Korean), passport English name, date of birth, gender, email, credit card number, credit card expiration date, membership number, passport number, passport number expiration date, passport nationality If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. Korea, America, Europe, Southeast Asia, Southwest Asia, China
P&S Taseco Vietnam Hanoi pick-up/sending vehicle reservation/confirmation Name (Korean/English), department, phone number, meeting time, hotel name, departure/arrival flight information, assigned department If required to be retained in accordance with relevant laws and regulations, the information will be retained for the required period. Vietnam, India

5. 개인정보 국외 이전 4. Matters Regarding the International Transfer of Personal Information

① The company transfers personal information collected from service users overseas as follows. Pursuant to Article 28-8, Paragraph 2 of the Personal Information Protection Act, the company provides the following information regarding the international transfer. If you decline international transfer, you will not be able to use the business trip management service. If you do not wish to transfer internationally, you can do so by canceling your membership.

Relevant Basis Personal information items transferred
Recipient of transfer
(Corporation name/Contact information manager)
Previous country Date of transfer Previous method transfer purpose Retention period
Article 28-8, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (Consent)

Name (Korean), name (English), nationality, date of birth, address, company name, department, rank, gender, credit card expiration date, contact information (company phone number), contact information (mobile phone number), email, member ID, password, credit card number, passport number expiration date, passport number
Samsung Hospitality America Incm
jyungmo.koo@samsung.com
USA Flight/Hotel/Rental Car
When making a reservation
SRS
System
Business trip management
service provided
Member
Until withdrawal
Samsung Hospitality U.K. Inc. /
shuk.security@samsung.com
uk
Samsung Hospitality Europe GmbH /
shuk.security@samsung.de
germany
Samsung Hospitality Romania S.R.L. /
shuk.security@samsung.com
Romania
Tianjin Samsung International Travel Service Co., Ltd /
changkeun.oh@samsung.com
china
Samsung Hospitality Philippines Inc. /
zzang_jjh@samsung.com
Philippines
Samsung Hospitality Vietnam Co., Ltd. /
kiwon126.oh@samsung.com
vietnam
Samsung Hospitality India Pvt. Ltd. /
chardonnay.shin@samsung.com
India

6. 개인정보 위탁 및 역외이전 5.Matters Concerning the Outsourcing of Personal Information Processing

① To ensure smooth operation, the Company outsources personal information processing to an external professional company as follows:

Entrustee (Trustee) Contents of the entrusted work
Hotel Shilla Operation and management of the data center where personal information is stored
First Trip Visa issuance and translation notarization agency
KICC (Korea Information and Communications Corporation) SRS service payment
KG Inicis SRS Service Payment
Cloud Square Call recording system maintenance
BizTalk SMS Transmission
Lulu Medic Traveler insurance subscription
BIS Traveler insurance subscription
Hankyul Translation Translation and notarization service
Move Vietnam pickup/sending vehicle service

② When entering into a consignment contract, the company, in accordance with Article 26 of the Personal Information Protection Act, specifies in the contract or other document matters regarding the prohibition of processing personal information for purposes other than those entrusted, technical and administrative protection measures, restrictions on re-entrustment, management and supervision of the consignee, and liability for damages. The company supervises the consignee to ensure the safe processing of personal information.

③ In accordance with Article 26, Paragraph 6 of the Personal Information Protection Act, if the consignee re-entrusts the company's personal information processing, the company's consent is obtained. The status of re-entrustment is as follows.

Entrustee Sub-Entrustee Sub-Entrusted Work
Hotel Shilla Samsung SDS Co., Ltd. (Sub-Entrustee: Miracom Inc.) Operation and Management of Data Centers Where Personal Information is Stored

④ If the entrusted company or entrusted tasks change, we will disclose it promptly through this policy.

6. 정보주체의 권리 및 그 행사방법 6. Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them

① Data subjects may request the Company to view, transfer, correct, delete, suspend processing, or withdraw consent to their personal information at any time (hereinafter referred to as "Exercise of Rights").

② The data subject may request to exercise his/her rights regarding his/her personal information processed by the company in the following ways.
- Visit the SRS system: Log in and click on 『My Page』 to exercise the data subject's rights
- Deletion (WEB): Visit the SRS system and log in and click on 『Service Inquiry > Withdraw Membership』 to exercise the data subject's rights
- Deletion (MOBILE): Log in to the SRS APP and click on 『My > Withdraw Membership』 to exercise the data subject's rights
- Contact the Personal Information Protection Officer in writing, by phone, or by email (10. Guidance on Personal Information Protection Officer and Manager)

③ The company will respond within 10 days (without delay in the case of a transfer request) from the date of receiving the request to exercise the rights from the data subject.

④ If the data subject or their legal representative requests correction of personal information errors, the personal information will not be used or provided until the correction is completed. Furthermore, if incorrect personal information has already been provided to a third party, we will notify the third party and take steps to ensure the correction.

⑤ Personal information deleted at the request of the data subject or their legal representative will be processed in accordance with "1. Purpose of Processing, Processed Items, Retention and Usage Period of Personal Information" and other laws and regulations, and will be processed so that it cannot be accessed or used for any other purpose.

⑥ The data subject's right to request access to and suspension of processing of personal information may be restricted by Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act. If the personal information is specifically designated as a subject of collection under other laws and regulations, the deletion of such personal information cannot be requested.

⑦ The company verifies whether the person exercising the rights is the data subject or a legitimate representative. Rights may be exercised through a legal representative or authorized agent, and in this case a power of attorney specified in the “Notice on Personal Information Processing Methods” [Appendix 11] must be submitted.

10. 개인정보보호를 위한 기술적/조직적 관리 7. Security Measures for Personal Information Protection

When processing customers' personal information, SBTM is taking the following technical, managerial, and physical measures to ensure the safety of personal information and prevent it from being lost, stolen, leaked, altered, or damaged.

① Minimization and training of employees handling personal information - We minimize the designation of personal information handlers, issue user accounts for each handler, and provide regular training.

② Conducting regular self-audits - We conduct self-audits on a regular basis to ensure the stability of personal information processing.

③ Establishment and implementation of an internal management plan - We have established and implemented an internal management plan for the safe processing of personal information.

④ Encryption of personal information - The user's password is encrypted, stored and managed, so only the user can know it.

⑤ Technical measures against hacking, etc. - To prevent leakage and damage of personal information due to hacking or computer viruses, we install security programs, update and inspect them periodically, install systems in areas where access from the outside is controlled, and monitor and block them technically and physically.


- Additionally, we are working to minimize personal information leakage by applying Internet blocking (network separation) to the personal information processing system operator PC.

⑥ Restrictions on access to personal information - We are establishing/applying password creation rules to record the details of granting, changing, and deleting access rights to the personal information processing system and to set and implement a secure password.

⑧ Retention and proteection against tampering of access records - In accordance with relevant laws and regulations, access records are retained and periodically inspected. Security features are employed to ensure that these records are not tampered with, stolen, or lost.

⑨ Use of locing devices for document secuirty - documents, auxilary storage media, and other items contatining personal information are stored in secure locations equipped with locking devices.

⑩ Access control for unauthorized personnel - Physical sotrage locations contatining personal information are kept seperate and access control procedures have been established and are being implemented.

11. 개인정보의 자동수집 장치의 설치, 운영 및 거부 8. Matters Concerning the Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

① The company operates ‘cookies’ that retrieve the information of the information subject when checking the same reservation schedule using the website. ② The information subject has the option to install cookies. *Cookies are very small text files that the server used to run the website sends to the user's browser and are sometimes stored on the subscriber's computer hard disk. ③ How to refuse cookie settings

* Example: To refuse cookie settings, the information subject can allow all cookies, confirm each time a cookie is saved, or refuse to save all cookies by selecting an option in the web browser used by the information subject.

- Google Chrome (https://support.google.com/chrome/answer/95647?hl=en-GB)

- Internet Explorer (https://support.microsoft.com/en-us/kb/260971)

- Mozilla Firefox (https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer)

- Safari (Desktop) (https://support.apple.com/kb/PH5042?locale=en_US)

- Safari (Mobile) (https://support.apple.com/en-us/HT201265)

- Android Browser (https://support.google.com/nexus/answer/54068?visit_id=0-636602363711055441-2350803723&hl=en&rd=1)

12. 행태정보의 수집·이용·제공 및 거부 등에 관한 사항 9. Matters Concerning the Collection, Use, Provision, and Refusal of Behavioral Information

The company does not collect, use, or provide behavioral information for online customized advertisements.

13. 개인정보에 관한 의견수렴 및 불만처리 10. Information on the Personal Information Protection Officer and Manager

① The company has designated a Personal Information Protection Officer as follows to oversee all personal information processing tasks and to handle complaints and provide remedies for damages related to personal information processing.

go.

▶ Personal Information Protection Officer
Name: Kim Jun-ki
Affiliation: SBTM
Position: Group Leader
Phone: 02-6048-8603
Email: sbtm.security@samsung.com

▶ Personal Information Protection Officer
Name: Bae Geon-il
Affiliation: SBTM
Position: Manager
Phone: 02-6048-8603
Email: sbtm.security@samsung.com

me.
- Data Protection Officer (DPO): Park Young-min
- Affiliation: Samsung Hospitality UK
- Contact: +44-1932-455-704
- Email: shuk.security@samsung.com

If you need to report or consult about other personal information, please contact the organizations below.
Personal Information Dispute Mediation Committee: (without area code) 1833-6972, https://www.kopico.go.kr/
- Personal Information Infringement Reporting Center: (without area code) 118, https://privacy.kisa.or.kr
- Supreme Prosecutors' Office Cyber ​​Investigation Division: (without area code) 1301, https://www.spo.go.kr
- National Police Agency Cyber ​​Investigation Bureau: (without area code) 182, https://ecrm.police.go.kr

Romanian supervisory bodies:
- The National Supervisory Authority for Personal Data Processing
- President: Mrs Ancuña Gianina Opre
- B-dul Magheru 28-30
- Sector 1, BUCURE?TI
- Tel.
- Fax +40 318 059 602
- e-mail: anspdcp@dataprotection.ro
- Website: https://www.dataprotection.ro/

UK supervisory bodies:
- The Information Commissioner’s Office
- Water Lane, Wycliffe House
- Wilmslow - Cheshire SK9 5AF
- Tel.
- Fax +44 01625 524510
- e-mail: international.team@ico.org.uk
- Website: https://ico.org.uk

German supervisory bodies:
- Der Bundesbeauftragte fur den Datenschutz und die Informationsfreiheit
- Graurheindorfer Str.
- 53117 Bonn
- Tel.
- e-mail: poststelle@bfdi.bund.de
- Website: https://www.bfdi.bund.de/

all.
- Personal information protection officer: Oh Chang-geun
- Affiliation: Samsung Hospitality China
- Contact: 189-0212-9657
- Email: changkeun.oh@samsung.com

③ Data subjects may contact the Personal Information Protection Officer and the relevant manager regarding any personal information protection-related inquiries, complaints, or remedies that arise while using the company's services. The company will respond and process inquiries without delay.

11. 권익침해 구제방법 11. Remedies for Rights Infringement

① Data subjects may request dispute resolution or consultation with the Personal Information Dispute Mediation Committee or the Korea Internet & Security Agency's Personal Information Infringement Report Center to seek redress for personal information infringement. For other inquiries or inquiries regarding personal information infringement, please contact the following organizations:
1. Personal Information Dispute Mediation Committee: (without area code) 1833-6972 (www.kopico.go.kr)
2. Personal Information Infringement Report Center: (without area code) 118 (privacy.kisa.or.kr)
3. National Police Agency: (without area code) 182 (ecrm.police.go.kr)

12. 권익침해 구제방법 12. Notice of Changes to the Personal Information Processing Policy

- Privacy Policy Version: v1.13
- Last Updated: May 20, 2026
The SBTM SRS Privacy Policy applies from May 20, 2025.