LOTTEJTB Privacy Policy

This Privacy Policy sets out how LOTTEJTB (“we”, “our” or “us”) collects, uses, stores and otherwise processes Personal Information defined in the applicable law in relation to the use of our services.

Local-specific clauses (Section 11) also apply to residents in those territories and may in some cases set out different standards due to applicable local laws and regulations. In the event that this creates a conflict between the local-specific clause and any other clause, the local-specific clause will govern.

In the event of conflict between the English version and other language version of this Privacy Policy, the English version shall prevail.

Table of contents

1.Categories of Personal Information we collect
2.Purposes for processing Personal Information
3.Sharing Personal Information
4.International Transfer
5.Retention
6.Security
7.Children
8.Privacy Rights
9.Changes to this Privacy Policy
10.Contact information
11.Local specific clauses
11.1Japan
11.2European Economic Area, United Kingdom and Switzerland
11.3United States
11.4Canada (including Québec)
11.5China
11.6South Korea
11.7Malaysia
11.8Indonesia
11.9Thailand
11.10India
11.11Philippines
11.12Vietnam
11.13Taiwan
11.14New Zealand
11.15Brazil

1 Categories of Personal Information we collect

1.1We collect the following Personal Information directly from you or indirectly through third parties, if any. Please note that Personal Information that we collect may differ depending on what service you use
1.1.1Personal Information collected directly from you
a.Your profile
(1)Full Name
(2)Phone Number
(3)Email Address
(4)Gender
(5)Nationality
(6)Residence Address
(7)Date of Birth
(8)Company’s name, department and title (If applicable)

<Collection method>

We collect the above information by asking you to provide them.

b.Information you register when you use our services
(1)Information about your travel (e.g., Place to stay, departure date, return date, number of guests, type of service, purpose of travel)
(2)Information about payment
(3)Emergency contact
(4)Passport information (optional)
(5)Dietary preferences including allergy information (optional)
(6)Disability Information (optional)
(7)Bank account information for refund
(8)Any other information you have provided to us in relation to your use of the services

<Collection method>

We collect the above information by asking you to provide them.

c.Responses to the survey

<Collection method>

We may ask you to participate in a survey. If you choose to answer the survey, we collect any information you provide in your responses.

d.Information collected through your use of the services
(1)IP address
(2)Information collected through Cookie or similar technologies (e.g., logs regarding the use of our website)
(3)Information about your usage of our services (e.g., date of service application)
(4)Other service usage history including browsing history

<Collection method>

We collect the above information automatically when you use our services or when you access to our website.

e.Information about your inquiry

<Collection method>

We collect the above information through your inquiry.

1.1.2Personal Information collected indirectly from third parties

We may receive Connecting Information (CI) from third parties where necessary to provide membership services and partnership-based services.

1.2Our services allow you to share certain details about your preferences, needs, or restrictions, such as “Dietary preferences including allergy information” or “Disability Information”, through various means including text boxes. Please note that any information you voluntarily provide through these means may reveal to us or to entities with which we share Personal Information (as outlined in “Section 3. Sharing Personal Information” below) certain information that may be classified as sensitive Personal Information under applicable laws. We do not use such sensitive Personal Information for marketing or promotional purposes. Sensitive Personal Information that you choose to submit is processed based on your consent, which you may withdraw at any time by contacting us using the details provided in “Section 10. Contact information” below.

2 Purposes for processing Personal Information

2.1We process your Personal Information for the purposes below.
a.To provide services you have asked us to provide to you.

This includes making necessary notifications and responding to your inquiry.

b.To improve and develop our services, marketing strategy and business.
c.To provide you with news, offers, promotions and advertisements (including those based on profiling of your interests and preferences) via email or online advertisements.
d.To protect interests and legal rights of us and our users.
e.To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar in accordance with our legal and regulatory obligations under the applicable law.
2.2The purposes for collecting and using each item of Personal Information are as set forth in Section 1 (Categories of Personal Information we collect)
2.3Where we collect your Personal Information to perform a contract with you, or where we have to collect Personal Information by law, provision of Personal Information is mandatory, and we will not be able to provide services to you without this information. In all other cases, provision of any requested Personal Information is optional, but not providing information may affect your ability to use the services or use particular aspects of the services if information is needed for those purposes.
2.4When we access your information stored on your device for the purpose that is not strictly necessary to provide our services, we obtain your consent. For example, when we collect information through Cookie for such purpose, we ask your consent in advance, and you can withdraw such consent at any time by accessing the Cookie setting page on our website.

3 Sharing Personal Information

We share your Personal Information with the following entities

Entities with whom we share Personal Information

Categories of Personal Information

Detail

JTB Group Companies

All categories of Personal Information listed in Section 1.

We share Personal Information with JTB Group Companies where those companies process it on our behalf to provide products and services to you, to conduct marketing and communication activities, or when it is necessary to perform a contract or to take steps.

Specific company names can be found below:

Japanese group companies

Overseas group companies

Business partners

“Your profile” and “Information you register when you use our services”.

We may share “Responses to the survey” and “Information about your inquiry” when they relate to Business Partners.

We share Personal Information with our business partners such as hotels and airline companies to provide you with our services. Business partners who receive such Personal Information differ depending on the travel plans booked by you but are limited to those partners necessary for us to provide travel services. If you would like to know the specific name of the business partners who receive your Personal Information, please contact us as indicated in Section 10 “Contact Information” below.

Service providers

All categories of Personal Information listed in Section 1.

We share Personal Information with service providers including professional advisors such as lawyers, travel service providers, electronic payment service providers, and system service providers including cloud service providers.

Advertising and Analytics Providers

All categories of Personal Information listed in the item a. and d. in the paragraph 1.1.1

We share Personal Information with advertising and analytics providers to provide you with news, offers, promotions and advertisements (including those based on profiling of your interests and preferences) via email or online advertisements.

Government or public authorities, law enforcement officials, courts, regulators or similar.

All categories of Personal Information listed in Section 1.

We may share Personal Information with government or public authorities, law enforcement officials, courts, regulators or similar if required by law, or if necessary for us to protect our legitimate interests, or the interests of others, in compliance with applicable laws.

Counterparty of Business transfer

All categories of Personal Information listed in Section 1.

In the event that we undertake a merger, acquisition, reorganization or disposal, Personal Information may be disclosed to any prospective purchaser and its advisers and will be passed to the new owners of the business.

4 International Transfer

We will process and store your Personal Information for the purposes outlined in this Privacy Policy in the Republic of Korea. In addition, we may transfer your Personal Information to other countries/regions when it is necessary for us to provide services to you.

Any transfers outside your country/region that do not provide an adequate level of data protection will be secured through appropriate contractual guarantees such as standard contractual clauses specified under the Regulation (EU) 2016/679 (General Data Protection Regulation)

5 Retention

We will retain Personal Information for as long as it is necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

In the event that we delete Personal Information after the above period or for any other reason, we irreversibly destroy Personal Information recorded and stored in electronic files, and shreds or incinerate any Personal Information recorded and stored by paper-based means.

6 Security

We have taken necessary and appropriate safety management measures to protect Personal Information, such as preventing leakage, loss, or damage. The main contents of these measures are as follows:

a.In order to comply with laws and regulations and ensure proper handling of Personal Information, we have formulated the Personal Information protection policies, and based on these policies, we have established this handling rule and other related internal rules concerning the acquisition, use, provision, and disposal of Personal Information.
b.We have appointed a Personal Information manager and a Personal Information officer, conducted mock training, and established a reporting system.
c.We conduct periodic self-inspections of the status of the handling of Personal Information and conduct audits by our audit department.
d.When outsourcing services, including the handling of Personal Information, we include clauses related to the handling of Personal Information in our contracts.
e.We provide regular training to our employees on the handling of Personal Information.
f.Matters concerning the confidentiality of Personal Information are described in our work rules and other internal rules.
g.We monitor access to and from our facilities, and establish rules for storage and disposal of documents and electronic media containing Personal Information.
h.Measures such as password protection and remote device control are implemented to prevent theft or loss of equipment.
i.Access control is implemented to limit the scope of databases handled by employees.
j.We have introduced mechanisms to protect the systems from unauthorized access from outside or from unauthorized software.
k.We store a part of Personal Information in certain foreign countries, such as the U.S, and Singapore, etc. We confirm the outline of the Personal Information protection legislation in such regions and take measures such as concluding a contract on the handling of Personal Information with a third party to whom we transfer Personal Information

7 Children

Our services are not directed to, and does not knowingly collect Personal Information from children. If you are a parent or guardian and are concerned that your child has provided us with Personal Information without your consent, you should contact us as indicated in Section 10 “Contact Information” below

8 Privacy Rights

8.1You have certain rights with respect to Personal Information depending on the applicable law. These may include the following rights;
a.Ask us for a copy of your Personal Information;
b.Correct, delete or restrict our processing of your Personal Information;
c.Obtain some Personal Information you provide to us in a structured, machine-readable format;
d.Object to our processing your Personal Information on the basis of our legitimate interests (or those of a third party), including processing for direct marketing or profiling for purposes of direct marketing; and
e.Where we have asked for your consent, to withdraw consent at any time. If you ask to withdraw your consent, this will not affect any processing which has already taken place at that time.
8.2You can exercise these rights by contacting us as indicated in Section 10 “Contact Information” below. These rights may be limited, for example, if fulfilling your request would reveal Personal Information about another person, or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping.
8.3If you have unresolved concerns, you have the right to complain to a data protection authority in the country.

9 Changes to this Privacy Policy

This Privacy Policy may be updated from time to time for any reason. We will notify you of any changes to this Privacy Policy and, where required by applicable law, request your consent to such changes.

10 Contact information

For requests to access Personal Information or inquiries regarding this Policy, you may contact the department below.

Personal Information Access Request Handling Department

Department

IT Planning

TEL

82-2-6313-8034

FAX

82-2-6313-8592

E-mail

privacy@lottejtb.com

Address

13Fl, Central Place, 50, Seosomun-ro, Jung-gu, Seoul, 04505, Korea

11 Local specific clauses

This section provides for certain local-specific amendments which may apply depending on which you are located or reside in and other factors set forth by local laws and regulations. The following provisions supplement the sections above. In case of a conflict or inconsistency, the specific local clause prevails.

In the event of any conflict between the English and local language versions of this Privacy Policy, the English version shall prevail.

11.1 Japan

a.We may provide your “Information related to Personal Information” defined in Act on the Protection of Personal Information (“APPI”) to third parties including data analysis companies and advertising companies for the purposes listed in Section 2, and such third parties may use such information in conjunction with your “Personal data” (defined in APPI) held by such third parties.
b.Joint use of Personal Information

We will share and jointly use the Personal Information of our customers/users as follows.

(1)Personal Information

Personal Information listed in Section 3.

(2)Scope of joint users

Our group companies (Please refer to the following for our group companies)

https://www.jtbcorp.jp/jp/jtb_group/

(3)Purpose of Joint Use

The purposes of joint use shall be included within the scope of the purpose of use mentioned in Section 3.

(4)Manager in charge of jointly use under Japanese law: LOTTEJTB
c.Transfer of Personal Information to a third party in a foreign country

In order to arrange travel services provided by transportation/accommodation facilities in the travel for which the customer applies or for the purpose of use as set forth in Section 3, we may, upon informing you of the country or region in which your Personal Information is to be provided, transfer Personal Information to transportation/accommodation facilities, service providers, or other third parties in the country or region above. In this case, it is as follows.

(1)Country or region to which Personal Information is transferred

We will inform you orally, by pamphlets, brochures, travel terms and conditions documents, notice documents, or websites, e-mails or other electromagnetic means.

(2)Systems for the protection of Personal Information in the above country or region and measures for the protection of Personal Information to be taken by a third party

Please see [https://www.jtbcorp.jp/jp/jtb_group/]

We may transfer Personal Information to a third party in a foreign country after taking measures such as concluding an agreement with such third party to implement appropriate measures for the protection of Personal Information.

d.Handling of anonymously processed information

We will take appropriate protective measures to prevent the identification of specific individuals and the restoration of such Personal Information used for production, and will prepare anonymously processed information and provide such information to third parties to the extent permitted by law.

(1)How to create anonymously processed information

When preparing anonymously processed information, we process the information appropriately according to the following in accordance with the standards stipulated by the Personal Information Protection Law and the Rules of the Personal Information Protection Committee.

Deleting a description that identifies a specific individual
Deleting an Individual Identification Code
Eliminating the sign that connects information with each other
Deleting unique descriptions, etc.
Taking other appropriate measures based on the nature of the Personal Information database, etc.
(2)Items included in anonymously processed information
Personal Attribute Information of Customers [Gender and Year of Birth of Representatives]
Information on use of us [Application date (month/year), Stores (prefecture/municipality/type), Travel information (departure date/return date, area, and accommodation facility (name/type), Number of users (by adult, male, female, and child), Product grade, product type, product form, travel purpose, and type of participation]
(3)Provision of anonymously processed information to a third party

Items and methods of provision of information included in anonymously processed information prepared by us and provided to third parties are as follows.

Items in (2) above
We will inform the recipients of such information that such data is anonymously processed information and provide such information after stipulating a contract to prevent improper handling of such information as identifying acts.
To provide anonymously processed information to a third party by a secure electromagnetic manner such as encrypting data files.
(4)Other safety management measures for anonymously processed information
Clarify the authority and responsibility of the person handling information such as the processing method.
We have established rules and regulations concerning the handling of such information, such as processing methods, and provide education and supervision to employees who handle such information.

11.2 European Economic Area, United Kingdom and Switzerland

a.We process your Personal Information for the following purposes. We also explain each legal basis in the table below.

Purpose

Legal Basis

To provide services you have asked us to provide to you.

This includes managing your payments, making necessary notifications and responding to your inquiry.

The processing is necessary to perform a contract or to take steps, at your request, prior to entering into a contract with you.

To analyse your use of the service in order to improve and develop our services, marketing strategy and business.

The processing is necessary for the purposes of the legitimate interests.

To provide you with news, offers, promotions and advertisements via email or online advertisements.

Consent.

You can withdraw your consent at any time by sending an e-mail to request for withdrawal to “us”.

To provide you with tailored news, offers, promotions and advertisements based on profiling of your interests and preferences via email or online advertisements.

Consent.

You can withdraw your consent at any time by sending an e-mail to request for withdrawal to “us”.

To protect interests and legal rights of us and our users.

The processing is necessary for the purposes of the legitimate interests.

To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar in accordance with our legal and regulatory obligations under the applicable law.

The processing is necessary for compliance with a legal obligation to which the controller is subject.

When the applicable law is other than those of your country of residence, we process your Personal Information for the purposes of the legitimate interests.

b.When we access your information stored on your device for the purpose that is not strictly necessary to provide our services, we obtain your consent. For example, when we collect information through Cookie for such purpose, we ask your consent in advance, and you can withdraw such consent at any time by accessing the Cookie setting page on our website.
c.If you live in France, you have a right to instruct us on the processing of your Personal Information after your death. You can change or revoke such instruction at any time.
d.Details of EU data protection authorities is available here and the website of the data protection authority of the UK Information Commissioner’s office is here.
e.We have designated the following domestic representative in the European Economic Area and the United Kingdom to process Personal Information:
Name of the entity: TUMLARE CORPORATION HUNGARY Travel Agent Ltd.
Address: H-1133 Budapest, Váci út 76.
E-mail: eurepresentative@jtb-europe.com

11.3 United States

11.3.1For residents of U.S. states excluding California
a.We set forth in our Privacy Policy, the categories of personal data we process. The purpose for processing Personal Information, the categories of Personal Information shared, and the categories of third parties with whom Personal Information is shared.
b.Consumers in certain states may have the following rights, and you can submit a request to exercise these rights by contacting us as indicated in Section 10 “Contact Information” above.
(1)Right to know and access

The tight to confirm whether we are processing Personal Information and to access such information. Residents in certain states may also obtain a list of third parties with whom we have shared personal data.

(2)Right to correct

The right to correct inaccurate Personal Information we hold about you.

(3)Right to delete

The right to delete the Personal Information provided by you or obtained about you.

(4)Right to access and data portability

The right to obtain a copy of the Personal Information previously collected by us and, to extent feasible, in a readily usable format to allow data portability.

(5)Right to appeal

If for any reason you would like to appeal a decision made by us relating to your request to exercise privacy rights, you have the right to submit an appeal to us. Please include your full name, the basis for your appeal and any other additional information to consider.

c.Consumers in certain states may also have the following rights:
(1)Right to Opt-out of Targeted Advertising and Sales

Some state laws may set forth the right to opt-out of advertising and analytics practices that may be considered “Targeted Advertising” or “Sale/Selling” of Personal Information under the applicable state law. To exercise the above right, please ensure that you may send an e-mail to request for opt-out to “us”, and you may also submit a request at: the Contact in Section 10.

(2)Right to Opt-out of Automated Decision Making and Profiling

While some state laws may set forth the right to opt-out of the automated decision making and profiling in furtherance of decisions that produce legal or similarly significant effects, we do not engage in such activities.

11.3.2For residents of California
a.California Consumer Rights
(1)Request to Know

Request information regarding what Personal Information we collect, use, disclose and sell, including the right to request that we provide you with the categories and specific pieces of Personal Information we have collected about you.

(2)Request to Correct

Request correction of inaccurate Personal Information that we maintain about you.

(3)Request to Delete

Request deletion of Personal Information that we maintain about you.

(4)“Do Not Sell or Share My Personal Information”

Request to opt-out of the “sale” of your Personal Information or the “sharing” of your Personal Information to a third party for cross-contextual behavioral advertising (i.e., targeted advertising).

(5)“Limit the Use and Disclosure of Sensitive Personal Information”

A consumer has the right to limit the use of the consumer’s sensitive Personal Information to certain purposes such as the purpose which is necessary to perform the services or provide the goods reasonably expected by on average consumer who requests such goods or services. We do not offer this right because we do use and disclose sensitive Personal Information only for such purposes.

b.Verifying Request

When making the above request, please provide us with enough information to allow us to verify you are the data subject of the Personal Information that we collected, or their authorized representative. You must also describe your request with enough detail so that we can understand, evaluate and respond to it.

When you exercise your Right to Know, Right to Delete, and /or Right to Correct, we may ask you to provide us with additional information to verify your identity and process your request. If we obtain such additional information, we may not be able to process the request.

c.Agent

If you are an authorized representative submitting a request on a consumer’s behalf, please complete the applicable request per the instructions below. We will follow up to request a signed, written permission signed by the individual who is the subject of the request. The written permission must state your full legal name, the full legal name of the individual who is the subject of the request, and a clear description of the permission granted. Alternatively, you may submit a copy of a power of attorney under applicable state law. Please keep in mind that if we do not receive adequate proof that you are authorized representative, we may deny the request.

d.Exercising Your Rights
(1)Request to Know, Correct and/or Delete

Please submit your request at: E-mail privacy@lottejtb.com

(2)Do Not Sell or Share My Personal Information

To opt-out of “sale” or “sharing” of your Personal Information for cross-context behavioral advertising, please contact us, and you may also submit a request at: Do Not Sell or Share My Personal Information.

e.Data Retention

We retain Personal Information for as long as it is necessary for the purposes outlined in this California Privacy Notice. However, we will keep the data for so long as is reasonably necessary if we are required to retain information by law.

f.Non-Discrimination

California consumers have the right to not receive discriminatory treatment for exercising CCPA rights. We will not discriminate against you for exercising your CCPA rights.

g.Notice of Financial Incentive

Under California regulations, if offer certain loyalty or similar program(s) directly or reasonably related to the collection, retention or deletion of your Personal Information, such program may be considered a “financial incentive”. In such case, we will be required to make additional disclosures to you, which we will provide when you agree to participate.

h.Personal Information We Collect and Purposes for Collection

The Personal Information we collect about you will depend upon you use services. Accordingly, we may not collect all of the below information. In addition to the below, we may collect and use additional type of information and will do so after providing notice to you and obtaining consent to the extent such notice and consent is required by applicable law.

We may have used Personal Information for the business or commercial purposes described in the following Table 1.

i.Additional Notice

Under the California “Shine the Light” law, you have the right to receive the following information:

(1)information identifying any third-party company to which we may have disclosed, within the past year, Personal Information pertaining to you and your family for the company’s direct marketing purposes
(2)a description of the categories of Personal Information disclosed.

To obtain such information, please email your request to us, and include your name, email address, mailing address or zip code, and a reference to “Your California Privacy Rights”.

[Table 1]

Categories of Personal Information

Purposes for collection of Personal Information

Categories of sources from which Personal Information was collected

To whom we may disclose Personal Information for a business purpose

Third Parties We Share with for Cross Context Behavioural Advertising

Identifiers:

Such as real name, postal address, email address, online identifier and IP address

To provide services you have asked us to provide to you.
To analyse your use of the service in order to improve and develop our services, marketing strategy and business.
To provide you with news, offers, promotions and advertisements (including those based on profiling of your interests and preferences).
To protect interests and legal rights of us and our users.
To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar.
Consumers
JTB Group Companies
Business Partners
Cookies or similar technologies
Business partners
Service providers
Government authorities, law enforcement officials, regulators, and court and similar.
Counterparty of Business transfer
Advertising and Analytics Providers

Commercial information:

Such as records of services purchased or considered and other purchasing or consuming histories or tendencies.

To provide services you have asked us to provide to you.
To analyse your use of the service in order to improve and develop our services, marketing strategy and business.
To provide you with news, offers, promotions and advertisements (including those based on profiling of your interests and preferences).
To protect interests and legal rights of us and our users.
To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar.
Consumers
JTB Group Companies
Business Partners

Business partners
Service providers
Government authorities, law enforcement officials, regulators, and court and similar.
Counterparty of Business transfer
Advertising and Analytics Providers

Internet or other electronic network activity information:

Such as browsing history and information regarding a consumer’s interaction with an internet website, application, or advertisement

To provide services you have asked us to provide to you.
To analyse your use of the service in order to improve and develop our services, marketing strategy and business.
To provide you with news, offers, promotions and advertisements (including those based on profiling of your interests and preferences).
To protect interests and legal rights of us and our users.
To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar.
Consumers
JTB Group Companies
Cookies or similar technologies
Business partners
Service providers
Government authorities, law enforcement officials, regulators, and court and similar.
Counterparty of Business transfer
Advertising and Analytics Providers

Inferences drawn from any of the information identified in this section to create a profile about a consumer reflecting the consumer’s preferences and characteristics.

To provide you with news, offers, promotions and advertisements (including those based on profiling of your interests and preferences).
Consumers
Government authorities, law enforcement officials, regulators, and court and similar.
Counterparty of Business transfer
Advertising and Analytics Providers

Sensitive Information:

Such as passport number, allergy information and disability information

To provide services you have asked us to provide to you.
To protect interests and legal rights of us and our users.
To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar.
Consumers
JTB Group Companies
Business partners
Service providers
Government authorities, law enforcement officials, regulators, and court and similar.
Counterparty of Business transfer
Advertising and Analytics Providers

Responses to the survey

To provide services you have asked us to provide to you.
To analyse your use of the service in order to improve and develop our services, marketing strategy and business.
To provide you with news, offers, promotions and advertisements (including those based on profiling of your interests and preferences).
To protect interests and legal rights of us and our users.
To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar.
Consumers
JTB Group Companies
Business partners
Service providers
Government authorities, law enforcement officials, regulators, and court and similar.
Counterparty of Business transfer
Advertising and Analytics Providers

Information about your inquiry

To provide services you have asked us to provide to you.
To analyse your use of the service in order to improve and develop our services, marketing strategy and business.
To provide you with news, offers, promotions and advertisements (including those based on profiling of your interests and preferences).
To protect interests and legal rights of us and our users.
To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar.
Consumers
JTB Group Companies
Business partners
Service providers
Government authorities, law enforcement officials, regulators, and court and similar.
Counterparty of Business transfer
Advertising and Analytics Providers

11.4 Canada (including Québec)

a.International Transfer

Through your use of our services, your Personal Information will be transferred outside of Canada or state where you live. Please see Section 3 for categories of recipients.

If your Personal Information is transferred to jurisdictions outside of Canada, it may be subject to the laws of those jurisdictions, which may allow access by courts, law enforcement, or government authorities in accordance with their laws.

You may obtain written information regarding our policies and practices with respect to service providers outside Canada, by sending an e-mail to us. You may also contact our e-mail (e-mail: privacy@lottejtb.com) for questions about the collection, use, disclosure, or storage of Personal Information by such service providers.

b.Profiling
c.We may use Personal Information for profiling. In such cases, we will inform you of the means to activate or deactivate profiling. You may also deactivate profiling by withdrawing your consent to our use of your data by sending an e-mail to us.
d.Your Rights

Subject to certain exceptions, you may have the following rights regarding your Personal Information in addition to the rights listed in Section 8:

Right to Access. Request to confirm the existence of the Personal Information, communicate it to you, and allow you to obtain a copy of it.

Right to Rectify. Request rectification of inaccurate, outdated or incomplete Personal Information we maintain about you.

Right to Withdraw Consent. Request to withdraw previously provided consent to the communication or use of the information collected.

11.5 China

a.We process your Personal Information that may fall under the definition of Sensitive Personal Information under Personal Information Protection Law such as allergy information. We process such information to provide our services based on your requests/preferences. Please note that providing such information is optional and we do not process such information to analyses your characteristics for business purposes other than the above.
b.We process your Personal Information for the following purposes. We also explain each legal basis in the table below.

Purpose

Legal Basis

To provide services you have asked us to provide to you.

This includes managing your payments, making necessary notifications and responding to your inquiry.

The processing is necessary to perform a contract or to take steps, at your request, prior to entering into a contract with you.

To analyse your use of the service in order to improve and develop our services, marketing strategy and business.

This processing is based on your consent to this Privacy Policy or separate consent on cookie settings.

For the latter, you can withdraw your consent at any time by accessing the Cookie setting page on our website.

To provide you with news, offers, promotions and advertisements via email or online advertisements.

Your separate consent.

You can withdraw your consent at any time by sending an e-mail to request for withdrawal to “us”.

To provide you with tailored news, offers, promotions and advertisements based on profiling of your interests and preferences via email or online advertisements.

Your separate consent.

You can withdraw your consent at any time by sending an e-mail to request for withdrawal to “us”.

To protect interests and legal rights of us and our users.

This processing is based on your consent to this Privacy Policy.

To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar in accordance with our legal and regulatory obligations under the applicable law.

We process Personal Information in order to comply with Chinese laws and regulations.

When the applicable law is other than Chinese laws, we process your Personal Information based on your consent to this Privacy Policy.

Where we collect the Personal Information based on your separate consent to this Privacy Policy, provision of any requested Personal Information is optional. In all other cases, provision of any requested Personal Information is mandatory, and we will not be able to provide services to you without this information.

11.6 South Korea

11.6.1.1Personal Information we collected
a.Personal Information Collected with Your Consent
(1)When you create an account

Personal Information

Purpose

Retention

Legal Basis

(Lotte Members Integration) Name, Email Address (ID), Mobile phone number, Address

To analyse service usage, provide personalized services and information, and send promotional and event notifications

Until you withdraw your consent or terminate the service

Consent (Article 15(1)(1) of the Personal Information Protection Act)

(Savings-type Cruise Program) Name, Mobile phone number

To analyse service usage, provide personalized services and information, and send promotional and event notifications

Until you withdraw your consent or terminate the service

Consent (Article 15(1)(1) of the Personal Information Protection Act)

(2)When you make a reservation for a product or service

Personal Information

Purpose

Retention

Legal Basis

Passport Number

To process travel product reservations, provide airline ticket consultation, booking and ticketing services, confirm eligibility for international travel, and provide visa application services

Until the completion of the trip

Applicable laws including the Personal Information Protection Act, Aviation Security Act, and Immigration Control Act

Health information (e.g., pregnancy or disability status), dietary restrictions, or other information that may affect the travel itinerary

Collected only where necessary to ensure the safe and smooth provision of travel services

<Additional Notice>

If you do not wish for us to retain such information, you may request the deletion of your Personal Information immediately after the travel service has ended.

Up to 1 year after the completion of the trip. However, information related to injuries or illnesses that occur during the trip will be deleted after insurance processing is completed.

Consent (Article 15(1)(1) of the Personal Information Protection Act)

(3)When you otherwise provide information to us voluntarily

Personal Information

Purpose

Retention

Legal Basis

Name, Mobile phone number, Address

To administer customer satisfaction surveys, conduct prize drawings, provide prizes, and handle related inquiries

Up to 2 months after survey completion. Winner information may be retained for up to 1 year.

Consent (Article 15(1)(1) of the Personal Information Protection Act)

(4)Information related to tour guides and partner companies

Personal Information

Purpose

Retention

Legal Basis

Resident Registration Number (RRN)

To establish, maintain, and terminate contracts, and to comply with obligations under applicable laws, including the Labor Standards Act, Income Tax Act, Social Insurance laws, and other relevant regulations

For 10 years after the termination of the contract, or for the period required under applicable laws and regulations

Income Tax Act Article 145 (Submission of Payment Records, etc.)

Biometric Information (Fingerprint Data)

To manage internal access control and security

For 1 month after the termination of the contract

Consent (Article 15(1)(1) of the Personal Information Protection Act)

b.Personal Information Collected Without Your Consent

- In certain cases, we may collect and process Personal Information without your consent where it is necessary to enter into or perform a travel service contract with you, or where otherwise permitted under applicable laws. This may include.

(1)When you create an account

Personal Information

Purpose

Retention

Legal Basis

(Lotte Members Integration) General Users: Name, Email Address (ID), Password, Mobile phone number, Date of birth, Gender, Address Corporate Users: Name (or Company Name), Email Address, Password, Address, Mobile phone number Foreign Users: Name, Email Address (ID), Password, Mobile phone number, Nationality, Date of birth, Gender

Account registration and management, prevention of duplicate registrations, and provision of membership services

Until membership termination. However, where retention is required to verify rights and obligations related to transactions under applicable laws (e.g., the Commercial Act), the information may be retained for the period required by such laws.

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

(Naver Login Integration) Name, Email Address, Date of birth, Mobile phone number, CI (Connecting Information)

To enable login and authentication through Naver social login integration

Until membership termination. However, where retention is required to verify rights and obligations related to transactions under applicable laws (e.g., the Commercial Act), the information may be retained for the period required by such laws.

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

(Savings-Type Cruise Program) Subscriber: Name, Date of birth, Address, Contact Information Account Holder: Name, Date of birth, Bank Name, Bank Account Number, Contact Information

Fee collection through CMS automatic debit, membership management, and provision of travel product information

3 years after service termination. However, where retention is required under applicable laws (e.g., the Commercial Act), the information may be retained for the legally required period.

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

(Lotte Members Integration – Optional) Name, Email Address (ID), Mobile phone number, Address

Service usage analysis, provision of personalized service information, and delivery of promotional and event information

Until you withdraw your consent or terminate the service

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

(Savings-Type Cruise Program – Optional) Name, Mobile phone number

Service usage analysis, provision of personalized service information, and delivery of promotional and event information

Until you withdraw your consent or terminate the service

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

(2)When you make or cancel a reservation

Personal Information

Purpose

Retention

Legal Basis

Name, Date of birth, Gender, Email Address, Mobile phone number

Travel product reservations, customer consultation, and service information

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Name, Date of birth, Gender, Visa/Passport possession status, Passport information (issue date, expiration date, nationality, issuing country), Mobile phone number

Travel product reservation, travel service use, and confirmation of eligibility for international travel

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Name, Date of birth, Gender, Passport/Visa possession status, Passport information (expiration date, nationality, issuing country), Mobile phone number Additional documents where applicable: • Passport copy and identification documents for discounted airfare reservations • Corporate card verification (card copy, business registration certificate or business card) • Family card verification (card copy and family relationship certificate)

Airline ticket consultation, reservation, and ticketing services

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Name, Gender, Age

Hotel consultation and reservation services

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Name, Passport information (issue date, expiration date, nationality, issuing country), Mobile phone number, Address, Emergency Contact, Stay Information

Visa application services

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Name, Date of birth, Gender, Driver’s License Type (Domestic)

Rental car consultation and reservation services

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Name, Date of birth, Gender

Travel insurance enrollment services

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Legal guardian’s Name, Relationship, Contact Information, Family Relationship Certificate

Verification of legal guardian identity and consent when making reservations for minors under the age of 14

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Name, Credit Card Information (card number, expiration date, first two digits of card password), Relationship with the contract holder, Bank Account Number, Account Holder Name

Payment, settlement, and refunds for travel products

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Name, Mobile phone number, Address

Payment, settlement, and refunds for Lotte JTB gift certificates

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Name, Date of birth, Mobile phone number, Lotte Membership Card Number

L.POINT accumulation

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Mobile phone number, Cash Receipt Card Number (for income deduction) Mobile phone number, Business Registration Number (for expense proof)

Issuance of cash receipts

5 years after the completion of the trip or for the period required under applicable laws. Airline Supporting Documents: Discount proof – 2 years after trip completion; Card proof – until the completion of the trip

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

(3)For other operational or administrative purposes

Personal Information

Purpose

Retention

Legal Basis

Name, Email Address (ID), Mobile phone number, Business Card Information

Provision of services for employees of affiliated companies

1 year from the date of registration or submission

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Provision of services for employees of affiliated companies

Travel consultation and quotation inquiries, Handling customer complaints and inconvenience reports

3 years from the date of registration or submission

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

(4)Information related to tour guides and partner companies

Personal Information

Purpose

Retention

Legal Basis

Name, Date of birth, Gender, Nationality, Address, Telephone Number, Mobile phone number

• Establishment, maintenance, and termination of contracts• Compliance with obligations under the Labor Standards Act, Income Tax Act, social insurance laws, and other applicable laws and regulations • Fulfillment of obligations under the Standard Terms and Conditions for Tourist Interpreter Guides • Issuance of system accounts for work purposes

10 years after the termination of the contract or until the retention period required by applicable laws and regulations

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Contract period, contract amount, payment details, bank account number

• Establishment, maintenance, and termination of contracts• Compliance with obligations under the Labor Standards Act, Income Tax Act, social insurance laws, and other applicable laws and regulations • Fulfillment of obligations under the Standard Terms and Conditions for Tourist Interpreter Guides • Issuance of system accounts for work purposes

10 years after the termination of the contract or until the retention period required by applicable laws and regulations

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

Tourist Interpreter Guide License Number

• Establishment, maintenance, and termination of contracts• Compliance with obligations under the Labor Standards Act, Income Tax Act, social insurance laws, and other applicable laws and regulations • Fulfillment of obligations under the Standard Terms and Conditions for Tourist Interpreter Guides • Issuance of system accounts for work purposes

1 month after the termination of the contract

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

(5)Information related to airline B2B partners

Personal Information

Purpose

Retention

Legal Basis

[Member] Business Registration Number, Business Name, Name of Representative, Telephone Number, Address, Bank Account Number for Deposit, Copy of Bankbook, Email Address for Receiving Tax Invoices, Copy of Business Registration Certificate

[Primary Administrator] Name, ID, Password, Telephone Number, Mobile phone number, Email Address

Issuance of system accounts for the use of related services such as ticketing requests and settlement

Until membership termination or until the retention period required by applicable laws and regulations

Article 15(1) of the Personal Information Protection Act (Performance of a Contract)

(6)Criteria for Additional Use and Provision
We may additionally use or provide Personal Information collected without the consent of the data subject in accordance with Article 15(3) or Article 17(4) of the Personal Information Protection Act, taking into consideration the matters set forth in Article 14-2 of the Enforcement Decree of the same Act.
In such cases, we will consider the following factors in determining whether additional use or provision without the data subject’s consent is permissible:
Whether the additional use or provision is related to the original purpose of collection (e.g., provision of travel services);
Whether the data subject can reasonably expect such use or provision in light of the circumstances of collection and processing practices
Whether the additional use or provision unfairly infringes upon the interests of the data subject;
Whether necessary measures have been taken to ensure security, such as minimizing the possibility of Personal Information exposure.
c.Personal Information Collected During Your Use of Our Services

- We may automatically collect certain Personal Information when you use our services or access our website

d.Connecting Information (CI)
(1)We may receive Connecting Information (CI) from third parties in order to provide membership services and partnership-based services. Such information is provided by the relevant service providers (partners) based on the prior consent of the data subject.
(2)We do not provide such information to third parties unless required by law or with the separate consent of the data subject.
(3)Data subjects may request access, correction, deletion, restriction of processing, and withdrawal of consent through the methods specified in “Section 10. Contact Information”.

Source of Collection

Purpose

Personal Information Provided

Retention

Lotte Members membership service

Naver airline service users

G-market airline service users

Connecting Information (CI)

Provision of membership and partnership services, user identification, reservation processing, and transaction fulfillment

Until the purpose of service provision is achieved or as required by applicable laws

e.How We Collect Personal Information

We collect Personal Information through various methods, including when you provide it through our website, by telephone or fax, through agreements with tour guides, or through partner companies, including when you submit information at your request.

11.6.2Provision of Personal Information to Third Parties

We process Personal Information of data subjects only within the scope specified for the purposes of processing. We provide Personal Information to third parties only where the data subject has given consent or where such provision is permitted under applicable laws, including Articles 17 and 18 of the Personal Information Protection Act. Otherwise, we do not provide Personal Information of data subjects to third parties.

a.Customer information

Recipient

Purpose

Personal Information Provided

Retention

Korean Air, Asiana Airlines, and other domestic and international airlines

[View Details]

Airline ticket reservation, issuance, payment services, and verification of eligibility for departure

[Booker] Name, Email, Mobile phone number, Card Information (Card Number, Expiration Date, First Two Digits of Card Password) [Traveler] Name, Date of birth, Gender, Email, Mobile phone number, Nationality, Passport Information (Passport Number, Passport Expiration Date, Country of Issue), Address of Stay, Airline Mileage Number Additional for Refund Requests: Bank Name, Account Number, Account Holder

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

Cruise Partners

[View Details]

Cruise reservation and verification of eligibility for departure

[Booker] Name, Email, Mobile phone number, Card Information (Card Number, Expiration Date, First Two Digits of Card Password) [Traveler] Name, Date of birth, Gender, Email, Mobile phone number, Nationality, Passport Information (Passport Number, Passport Expiration Date, Country of Issue)Additional for Refund Requests: Bank Name, Account Number, Account Holder

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

HotelPass

Agency service for domestic and overseas accommodation reservations

[Booker] Name, Email, Mobile phone number, Card Information (Card Number, Expiration Date, First Two Digits of Card Password) [Traveler] Name, Gender, Age

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

Local Tour Operators (Land Operators)

[View Details]

Operation of domestic and overseas events and customer management

[Traveler] Name, Contact Information, Date of birth, Email, Passport Information (Passport Number, Expiration Date)

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

MOVV

Provision of private transportation services

Name, Contact Information

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

HanaTour

Travel product reservation processing and confirmation

[Booker] Name, Mobile phone number, Email [Traveler] Name, Mobile phone number, Date of birth, Gender, Passport Information (Passport Number, Expiration Date)

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

Kumho Buslines Tourism

Provision of chartered bus services

Name, Contact Information, Email

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

Naver

Reservation confirmation and accumulation of promotional/event points

Naver User Unique Identifier, Last Four Digits of Mobile phone number, Airline Ticket and Travel Product Reservation Information

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

Lotte Insurance, ACE American Fire & Marine Insurance

Enrollment in travel insurance and identity verification when claiming insurance benefits

Name, Date of birth, Gender

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

Linktivity

Activity reservations, individual bookings, and service operation

Name, Date of birth For transfer reservations: Accommodation Information, Arrival/Departure Date Information, Local Contact Information For reservations including meals: Allergies For diving experience reservations: Possession and level of diving certification When verification of participation eligibility is required: Health condition

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

JTB GMT

JR Pass reservation and issuance

Name

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

Guides / Tour Conductors

Travel guidance and tour management

Name, Contact Information

Until the termination of the travel contract or for the mandatory period required under applicable laws and regulations

National Tax Service

Issuance of cash receipts

For income deduction: Mobile phone number, Cash Receipt Card Number For expense proof: Mobile phone number, Business Registration Number

b.Tour guide information

Recipient

Purpose

Personal Information Provided

Retention

Korea Workers’ Compensation & Welfare Service

Insurance eligibility verification and year-end insurance premium settlement

Name, Resident Registration Number, Contact Information, Contract Status, Occupation, Contract Date, Contract End Date, Monthly Salary, Annual Income

Until the purpose of use has been achieved or for the period required under applicable laws and regulations

Shinhan Bank, KB Kookmin Bank, Hana Bank

Payment of contract amount

Name, Bank Account Number, Salary Bank, Salary Amount

Until the purpose of use has been achieved or for the period required under applicable laws and regulations

11.6.3 Entrustment of Personal Information Processing and List of Service Providers

In accordance with Article 26 of the Korean Personal Information Protection Act, the Company specifies in contracts and other relevant documents the purpose of data processing, prohibition of processing beyond the scope of the entrusted tasks, technical and administrative security measures, restrictions on sub-entrustment, supervision of entrusted parties, and liability for damages. The Company monitors entrusted parties to ensure the secure processing of Personal Information.

a. Service Providers (Processors)

Service Providers (Processors)

Processing Activities

Lotte Members Co., Ltd.

Identity verification service

Lotte Innovate Co., Ltd.

Development and maintenance of the product reservation management system

NS Soft

Development and maintenance of the installment cruise customer management system

Taesung Innovation

Maintenance of telecommunication equipment, electrical equipment, and call recording systems

TOPAS

Development and maintenance of the airline reservation management system

NICE Information Service Co., Ltd.

Identity verification and foreigner status verification

KG Inicis Co., Ltd.

Payment processing service

KS-NET

Credit card payment authorization and automatic deposit service for sales transactions

Namie

Production of guide business cards

Winning

Visa processing agency service

Hyphen Corporation

Firm banking (corporate banking integration) service

Toss Payments Inc.

Payment processing service

b.Sub-processors

Processor

Sub-processor

Processing Activities

KG Inicis Co., Ltd.

KS Korea Employment Information Co., Ltd.

Customer consultation support

Toss Payments Inc.

Toss CX Co., Ltd.

Customer center operation

Toss Payments Inc.

Wise Infotech Co., Ltd.

Operation and maintenance of the electronic payment system

Toss Payments Inc.

Avercus Co., Ltd.

Operation and maintenance of the electronic payment system

Toss Payments Inc.

KOVAN Co., Ltd.

intermediation of transaction details (when using payment terminals)

Toss Payments Inc.

T Scientific Co., Ltd.

Server and system monitoring

Toss Payments Inc.

Comtec Systems Co., Ltd.

Operation of network equipment and security equipment

Toss Payments Inc.

Amazon Web Services Inc.

Operation of cloud infrastructure

Toss Payments Inc.

Coocon Co., Ltd.

Bank account validity verification

Toss Payments Inc.

Hecto Financial Co., Ltd.

Processing of bank transfer payments (when using virtual accounts)

11.6.4Disclosure of Personal Information in Emergency Situations

We may disclose Personal Information to relevant authorities without the consent of the data subject in emergency situations, including but not limited to disasters, infectious diseases, incidents or accidents that pose an imminent threat to life or bodily safety, or situations involving an imminent risk of significant property loss. Personal Information may also be disclosed without the data subject’s consent when required for investigative purposes or upon request from competent authorities in accordance with applicable laws and regulations.

Category

Recipient

Purpose

Legal Basis

Disaster Response

Central Disaster and Safety Countermeasures Headquarters or Local Disaster and Safety Countermeasures Headquarters

Name, Resident Registration Number, Address, Telephone Number (including mobile phone number)

Article 74-3 of the Framework Act on the Management of Disasters and Safety (Request for Information, etc.)

Disaster Response

Central Disaster and Safety Countermeasures Headquarters or Local Disaster and Safety Countermeasures Headquarters

Information required for tracking movement routes and for search and rescue, including:

Article 74-3 of the Framework Act on the Management of Disasters and Safety (Request for Information, etc.)

Disaster Response

Central Disaster and Safety Countermeasures Headquarters or Local Disaster and Safety Countermeasures Headquarters

a. Information collected through CCTV

Article 74-3 of the Framework Act on the Management of Disasters and Safety (Request for Information, etc.)

Disaster Response

Central Disaster and Safety Countermeasures Headquarters or Local Disaster and Safety Countermeasures Headquarters

b. Public transportation card usage records

Article 74-3 of the Framework Act on the Management of Disasters and Safety (Request for Information, etc.)

Disaster Response

Central Disaster and Safety Countermeasures Headquarters or Local Disaster and Safety Countermeasures Headquarters

c. Credit card, debit card, and prepaid card transaction date/time and location

Article 74-3 of the Framework Act on the Management of Disasters and Safety (Request for Information, etc.)

Disaster Response

Central Disaster and Safety Countermeasures Headquarters or Local Disaster and Safety Countermeasures Headquarters

d. Name and telephone number of the medical institution on prescriptions, and treatment date/time in medical records

Article 74-3 of the Framework Act on the Management of Disasters and Safety (Request for Information, etc.)

Prevention and Control of Infectious Diseases

Korea Disease Control and Prevention Agency (KDCA) or Metropolitan/Provincial Governments

Name, Resident Registration Number, Address, Telephone Number (including mobile phone number)

Article 76-2 of the Infectious Disease Control and Prevention Act (Request for Provision and Confirmation of Information)

Prevention and Control of Infectious Diseases

Korea Disease Control and Prevention Agency (KDCA) or Metropolitan/Provincial Governments

Prescriptions and medical records pursuant to the Medical Service Act

Article 76-2 of the Infectious Disease Control and Prevention Act (Request for Provision and Confirmation of Information)

Prevention and Control of Infectious Diseases

Korea Disease Control and Prevention Agency (KDCA) or Metropolitan/Provincial Governments

Immigration records for the period designated by the Commissioner of KDCA

Article 76-2 of the Infectious Disease Control and Prevention Act (Request for Provision and Confirmation of Information)

Prevention and Control of Infectious Diseases

Korea Disease Control and Prevention Agency (KDCA) or Metropolitan/Provincial Governments

Other information required to trace movement routes, including:

Article 76-2 of the Infectious Disease Control and Prevention Act (Request for Provision and Confirmation of Information)

Prevention and Control of Infectious Diseases

Korea Disease Control and Prevention Agency (KDCA) or Metropolitan/Provincial Governments

a. Credit, debit, and prepaid card transaction records under the Specialized Credit Financial Business Act

Article 76-2 of the Infectious Disease Control and Prevention Act (Request for Provision and Confirmation of Information)

Prevention and Control of Infectious Diseases

Korea Disease Control and Prevention Agency (KDCA) or Metropolitan/Provincial Governments

b. Public transportation card usage records under the Act on the Promotion of Public Transportation Use

Article 76-2 of the Infectious Disease Control and Prevention Act (Request for Provision and Confirmation of Information)

Prevention and Control of Infectious Diseases

Korea Disease Control and Prevention Agency (KDCA) or Metropolitan/Provincial Governments

c. Video information collected through video information processing devices under the Personal Information Protection Act

Article 76-2 of the Infectious Disease Control and Prevention Act (Request for Provision and Confirmation of Information)

Protection of Persons at Risk of Suicide

Police Agencies

Name, Resident Registration Number (or date of birth if unavailable), Address, Telephone Number, ID, Email Address, and Personal Location Information of the person requiring emergency rescue

Article 19-3 of the Suicide Prevention Act (Request for Provision of Information for Rescue of Emergency Rescue Targets)

Protection of Persons at Risk of Suicide

Korea Coast Guard

Name, Resident Registration Number (or date of birth if unavailable), Address, Telephone Number, ID, Email Address, and Personal Location Information of the person requiring emergency rescue

Article 19-3 of the Suicide Prevention Act (Request for Provision of Information for Rescue of Emergency Rescue Targets)

Protection of Persons at Risk of Suicide

Fire Departments

Name, Resident Registration Number (or date of birth if unavailable), Address, Telephone Number, ID, Email Address, and Personal Location Information of the person requiring emergency rescue

Article 19-3 of the Suicide Prevention Act (Request for Provision of Information for Rescue of Emergency Rescue Targets)

Processing of Personal Information Related to Crimes such as Kidnapping or Illegal Confinement

Police Agencies

Video information such as CCTV footage

Article 18(2) of the Personal Information Protection Act (Restriction on Use and Provision of Personal Information for Purposes Other Than the Intended Purpose)

Investigation Purposes

Police Agencies

Personal Information items requested by relevant authorities

Article 199 of the Criminal Procedure Act (Measures Necessary for Investigation)

Investigation Purposes

Korea Coast Guard

Personal Information items requested by relevant authorities

Article 199 of the Criminal Procedure Act (Measures Necessary for Investigation)

Investigation Purposes

Prosecution Service

Personal Information items requested by relevant authorities

Article 199 of the Criminal Procedure Act (Measures Necessary for Investigation)

Investigation Purposes

National Intelligence Service

Personal Information items requested by relevant authorities

Article 199 of the Criminal Procedure Act (Measures Necessary for Investigation)

11.6.5Overseas transfer of Personal Information

In accordance with Article 28-8(1)3 of the Korean Personal Information Protection Act, the Company may transfer your Personal Information to, or entrust the processing of such Personal Information to, organizations located outside the Republic of Korea.

Recipient

Country

Timing and Method of Transfer

Personal Information Transferred

Purpose

Retention

Contact of Data Protection Officer

AMADEUS

Spain

Transmitted via network at the time of service use

Name, Date of birth, Gender, Contact information, Email, Emergency contact, Passport number, Nationality, Passport issuing country, Passport expiration date, Card number, Expiration date, (for virtual account payment) Transaction authentication number, (for bank transfer) Transaction number

Processing and confirmation of reservations and provision of payment services

Within 5 years from the date of provision or until the termination of the contract

dataprotection@amadeus.com

Asiana Sabre

United States

Transmitted via network at the time of service use

Name, Date of birth, Gender, Contact information, Email, Emergency contact, Passport number, Nationality, Passport issuing country, Passport expiration date, Address of stay, ZIP code

Processing and confirmation of reservations and provision of payment services (for card payments)

Within 5 years from the date of provision or until the termination of the contract

privacy@sabre.com

Korean Air, Asiana Airlines, and other domestic and international airlines

[View Details]

Varies by airline

Transmitted via network at the time of service use

[Booker] Name, Email, Mobile phone number, Card information (card number, expiration date, first two digits of card password) [Traveler] Name, Date of birth, Gender, Email, Mobile phone number, Nationality, Passport information (passport number, expiration date, country of issue), Address of stay, Airline mileage number Additional for refund requests: Bank name, Account number, Account holder

Airline ticket reservation, issuance, payment services, and verification of eligibility for departure

Until the termination of the travel contract or for the period required under applicable laws and regulations

Refer to the relevant airline’s website

Cruise Partners

[View Details]

Varies by partner

Sent via email at the time of service use

[Booker] Name, Email, Mobile phone number, Card information (card number, expiration date, first two digits of card password) [Traveler] Name, Date of birth, Gender, Email, Mobile phone number, Nationality, Passport information (passport number, expiration date, country of issue) Additional for refund requests: Bank name, Account number, Account holder

Cruise reservation and verification of eligibility for departure

Until the termination of the travel contract or for the period required under applicable laws and regulations

Refer to the relevant partner’s website

HANKOOK HAWAII, INC. (Local Tour Operator)

United States

Sent via email at the time of service use

[Traveler] Name, Contact information, Date of birth, Email, Passport information (passport number, expiration date)

Event operation and customer management

Until the termination of the travel contract or for the period required under applicable laws and regulations

goodhawaii@gmail.com

SIXT

Germany / United States

Transmitted via network at the time of service use

For rental car reservations: Name, Email address, Mobile phone number, Flight number For chauffeur service reservations: Name, Email address, Mobile phone number, Billing address, (for card payments) Card number, Expiration date

Reservation processing and confirmation, and provision of payment services

Within 5 years from the date of provision or until the termination of the contract

dennis.john@sixt.co.kr

Linktivity

Japan

Transmitted via network at the time of service use

Name, Date of birth For transfer reservations: Accommodation information, Arrival/departure date information, Local contact information For reservations including meals: Allergies For diving experience reservations: Possession and level of diving certification When participation eligibility verification is required: Health condition

Activity reservations and individual service bookings

Within 5 years from the date of provision or until the termination of the contract

JTB GMT

Japan

Transmitted via network at the time of service use

Name

JR Pass reservation and issuance

10 years from the date of provision

private@jtb.com

11.6.6Retention

Purpose

Legal Basis

Retention

Records related to contracts or withdrawal of subscription (cancellation)

Article 6 of the Act on the Consumer Protection in Electronic Commerce

5 years

Records related to payment and supply of goods or services

Article 6 of the Act on the Consumer Protection in Electronic Commerce

5 years

Records related to consumer complaints and dispute resolution

Article 6 of the Act on the Consumer Protection in Electronic Commerce

3 years

Records related to labeling and advertising

Article 6 of the Act on the Consumer Protection in Electronic Commerce

6 months

Records related to access logs

Article 15-2 of the Protection of Communications Secrets Act

3 months

11.6.7Personal Information of Children Under the Age of 14
a.The Company defines a child as a person under the age of 14. If a parent or legal guardian suspects that a child has provided Personal Information without the consent of the legal guardian, the parent or legal guardian may contact the Company using the contact information provided in Section 10.
b.The Company processes the Personal Information of children under the age of 14 only when a legal guardian makes a reservation for travel products that include such child. In such cases, the Company obtains the consent of the legal guardian for the processing of the child’s Personal Information through one of the following methods:
(1)By allowing the legal guardian to indicate consent on a website where the consent details are posted and notifying the legal guardian via SMS that the Company has confirmed such consent.
(2)By providing a written document containing the consent details directly to the legal guardian, or delivering it by mail or fax, and receiving the signed or sealed document from the legal guardian.
(3)By sending an email containing the consent details and receiving an email from the legal guardian indicating consent.
(4)By informing the legal guardian of the consent details by telephone and obtaining consent verbally.
(5)By any other method equivalent to the above that informs the legal guardian of the consent details and verifies the expression of consent.
11.6.8Procedures and Methods for the Destruction of Personal Information
a.We destroy Personal Information without delay once the purpose of use of the collected Personal Information has been achieved. Where Personal Information must be retained for a certain period pursuant to applicable laws and regulations despite the achievement of the purpose of use, such information shall be stored for the required period and then destroyed. The procedures and methods for destruction are as follows:
(1)Destruction Procedures
Personal Information provided by the data subject for membership registration and use of travel services shall be destroyed or deleted without delay once the purpose of use has been achieved, unless the information is required to be retained for a certain period pursuant to applicable laws and regulations.
Destruction Methods
Personal Information printed on paper: Destroyed by shredding or incineration.
Personal Information stored in electronic file format: Permanently destroyed using technical methods that render the records unrecoverable and unusable.
11.6.9Notice Regarding Automated Decision-Making
a.“Automated decision-making” refers to decisions that are made through automated processing systems and that produce legal effects concerning the data subject or similarly significantly affect the data subject.
b.We may use automated decision-making in the course of providing certain services. In such cases, the Company clearly informs the data subject of the logic involved in such decisions and the significance and expected consequences of the decision for the data subject.
11.6.10Rights of Data Subjects
a.Data subjects may exercise the following rights with respect to their Personal Information at any time:
(1)The data subject’s Personal Information held by the Company;
(2)Details regarding the Company’s use of the data subject’s Personal Information or provision of such Personal Information to third parties; and
(3)Details regarding the data subject’s consent to the collection, use, and provision of Personal Information.
(4)Requests to exercise the above rights may be made through the following methods:
Inquiry and Correction: Via the Company’s website (login required) → Edit Personal Information / Edit Membership Information
Deletion and Withdrawal of Membership: Via the Company’s website (login required) → My Page → Membership Information → Withdraw Membership
Withdrawal of Consent to Receive Promotional Information: Via the Company’s website (login required) → Edit Personal Information → Marketing Information Consent
Other Requests: By contacting customer service through telephone consultation or other designated customer support channels.

※ Requests to access or otherwise exercise rights regarding the Personal Information of children under the age of 14 must be made directly by their legal representatives.

For minors aged 14 or older, the data subject may exercise such rights directly or through a legal representative.

b.Data subjects may have the following rights regarding automated decision-making
(1)The right to request an explanation of the logic involved, as well as the significance and expected consequences of such automated decisions
(2)The right to request human intervention in the automated decision-making process
(3)The right to object to automated decisions
(4)The right to request a review of decisions made through automated processing
c.Data subjects may exercise their rights by submitting a request to the Company in writing, by email, fax, or other methods in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take prompt action upon receiving such requests.
d.These rights may also be exercised through a legal representative or an authorized agent. In such cases, a power of attorney must be submitted in accordance with Form No. 11 of the Notice on the Methods of Processing Personal Information (No. 2020-7).
e.Requests for access to Personal Information or suspension of processing may be restricted in accordance with Article 35(4) and Article 37(2) of the Personal Information Protection Act.
f. Requests for deletion may also be restricted where the Personal Information must be retained under other applicable laws.
g.When data subjects request access, correction, deletion, or suspension of processing of Personal Information, the Company verifies whether the requester is the data subject or a duly authorized representative.
h.Data subjects are responsible for protecting their own Personal Information. The Company shall not be liable for any issues arising from the user's negligence, such as sharing IDs or passwords or leaving a device unattended while logged in, unless such issues are attributable to the Company’s intentional misconduct or negligence.
(1)Data subjects must ensure that their Personal Information is accurate and up to date, and any consequences arising from inaccurate information are the responsibility of the user.
(2)User IDs and passwords must be used only by the user and may not be transferred or lent to third parties.
(3)If a person registers as a member or purchases products using another person’s Personal Information, the membership may be revoked and legal action may be taken in accordance with applicable laws.
11.6.11Matters Concerning the Installation, Operation, and Refusal of Personal Information Collection Devices
a.We use cookies to provide users with convenient services. Cookies are small pieces of information that a website sends to a user’s computer browser.
b.Data subjects may allow or refuse the storage of cookies by adjusting the settings of their web browser. However, refusal to store cookies may cause difficulties in using certain services.
c.Methods for refusing the collection of cookies are as follows:
(1)Web Browsers
Microsoft Edge: Settings → Privacy, search, and services → Tracking prevention → Select the level of tracking prevention
Google Chrome: Settings → Privacy and security → Cookies and other site data → Block third-party cookies
Safari: Settings → Advanced → Block all cookies
(2)Mobile Devices
Android
Chrome: Settings → Site settings → Cookies → Allow or block cookies
Samsung Internet: Settings → Browsing data → Delete browsing data → Select cookies and site data → Delete data
iOS
Chrome: Settings → Privacy → Clear browsing data → Select cookies and site data → Clear browsing data
Safari: Settings → Safari → Advanced → Block all cookies
11.6.12Linked Websites
a.We may provide data subjects with links to websites or materials of other companies. In such cases, we have no control over the external websites or materials and does not assume any responsibility or provide any guarantee with respect to the services, accuracy, reliability, or usefulness of the information or materials provided on such websites.
b.Our Privacy Policy does not apply to linked websites other than our official website. If you access another company’s website by clicking a link provided us, you are advised to review the privacy policy of the relevant website.
11.6.13Personal Information Protection Officer and Person in Charge
a. We assume overall responsibility for matters related to the processing of Personal Information and, in order to address complaints from data subjects and provide remedies for damages related to Personal Information processing, has designated a Personal Information Protection Officer and a person in charge of Personal Information protection as follows:

Category

Personal Information Protection Officer (CPO)

Person in Charge of Personal Information Protection

Name

Lee, Junyoung

Kim,Nay

Department

Management Support Division

IT Planning

Telephone

1577-6511

02-6313-8034

FAX

02-6313-8592

E-mail

privacy@lottejtb.com

Address

13Fl, Central Place, 50, Seosomun-ro, Jung-gu, Seoul, 04505, Korea

11.6.14 Remedies for Infringement of Rights

Data subjects may apply for dispute resolution, consultation, or other remedies regarding Personal Information infringement to the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Center of the Korea Internet & Security Agency (KISA), or other relevant institutions.

For reports or consultations related to Personal Information infringement other than those listed below, please contact the relevant institutions as follows:

(1)Personal Information Dispute Mediation Committee

Telephone: (No area code) 1833-6972, Website: https://www.kopico.go.kr

(2)Personal Information Infringement Report Center (KISA)

Telephone: (No area code) 118, Website: https://privacy.kisa.or.kr

(3)Supreme Prosecutors’ Office

Telephone: (No area code) 1301, Website: https://www.spo.go.kr

(4)Korean National Police Agency (Cyber Crime Report Center)

Telephone: (No area code) 182, Website: https://ecrm.cyber.go.kr

11.7 Malaysia

a.In addition to the rights stated in Section 8.1, you also have the right to prevent processing for a specified purpose in a specified manner if the same may cause damage or distress and the right to prevent processing for the purposes of direct marketing.

11.8 Indonesia

a.We process your Personal Information for the following purposes. We also explain each legal basis in the table below.

Purpose

Legal Basis

To provide services you have asked us to provide to you.

This includes managing your payments, making necessary notifications and responding to your inquiry.

The processing is necessary to perform a contract or to take steps, at your request, prior to entering into a contract with you.

To analyse your use of the service in order to improve and develop our services, marketing strategy and business.

The processing is necessary for the purposes of the legitimate interests.

To provide you with news, offers, promotions and advertisements via email or online advertisements.

Consent.

You can withdraw your consent at any time by sending an e-mail to request for withdrawal to us

To provide you with tailored news, offers, promotions and advertisements based on profiling of your interests and preferences via email or online advertisements.

Consent.

You can withdraw your consent at any time by sending an e-mail to request for withdrawal to us

To protect interests and legal rights of us and our users.

The processing is necessary for the purposes of the legitimate interests.

To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar in accordance with our legal and regulatory obligations under the applicable law.

The processing is necessary for compliance with a legal obligation to which the controller is subject.

To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar in accordance with our legal and regulatory obligations under the applicable laws other than Indonesian laws.

The processing is necessary for the purposes of the legitimate interests.

b.Your Rights

Under Personal Data Protection Law of Indonesia, subject to certain exceptions, you may have the following rights regarding your Personal Information in addition to the rights listed in Section 8:

(1)Right to Inform/Access. Request to confirm the existence of the Personal Information, communicate it to you, and allow you to obtain a copy of it.
(2)Right to Rectify. Request rectification of inaccurate Personal Information we maintain about you.
(3)Right to Withdraw/Restrict Processing. Request to withdraw previously provided consent to process your Personal Information.
(4)Right not be subject to a decision based solely on automated processing
(5)Right to obtain clear information regarding identity clarity, basis of legal interest, purpose of requesting and using Personal Information, and accountability of the party requesting Personal Information; and
(6)Right to sue and receive compensation for violations of Personal Information processing about you.

11.9 Thailand

a.We have designated the following domestic representative for the processing of Personal Information:
Name of entity: JTB (Thailand) Limited
Address: 54 Harindhorn Building, 9th Floor, Room 9C, 9D, 9E North Sathorn Road, Silom, Bangrak, Bangkok 10500 THAILAND
E-mail: dpo.th@jtbap.com

11.10 India

a.In certain cases, we may process your Personal Information on the legal basis of legitimate use, as permitted under the Digital Personal Data Protection Act 2023 of India (“DPDPA”). This includes situations where you have voluntarily shared your Personal Information with us for certain specified purposes and have not indicated to us that you do not consent to its use.
b.If you have any complaints or grievances regarding the processing of your Personal Information or the exercise of your rights under the DPDPA, please contact us using the details provided in Section 10. If your complaint or grievance remains unresolved, you may file a complaint with the Data Protection Board of India, as provided under the DPDPA.

11.11 Philippines

a.We process your Personal Information for the following purposes. We also explain each legal basis in the table below.

Purpose

Legal Basis

To provide services you have asked us to provide to you.

This includes managing your payments, making necessary notifications and responding to your inquiry.

The processing is necessary to perform a contract or to take steps, at your request, prior to entering into a contract with you.

To analyse your use of the service in order to improve and develop our services, marketing strategy and business.

The processing is necessary for the purposes of the legitimate interests.

To provide you with news, offers, promotions and advertisements via email or online advertisements.

Consent.

You can withdraw your consent at any time by sending an e-mail to request for withdrawal to us

To provide you with tailored news, offers, promotions and advertisements based on profiling of your interests and preferences via email or online advertisements.

Consent.

You can withdraw your consent at any time by sending an e-mail to request for withdrawal to us.

To protect interests and legal rights of us and our users.

The processing is necessary for the purposes of the legitimate interests.

To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar in accordance with our legal and regulatory obligations under the applicable law.

The processing is necessary for compliance with a legal obligation to which the controller is subject.

To respond to requests from government or public authorities, law enforcement officials, courts, regulators or similar in accordance with our legal and regulatory obligations under the applicable laws other than Philippine laws.

The processing is necessary for the purposes of the legitimate interests.

b.In addition to the rights stated in Section 8.1, you also have the following rights:
(1)Right to be informed whether Personal Information pertaining to you shall be, are being, or have been processed, including the existence of automated decision-making and profiling;
(2)Right to object to the processing of your Personal Information for direct marketing, profiling, or in cases of automated processing where the personal data will, or is likely to, be made as the sole basis for any decision that significantly affects or will affect you;
(3)Right to dispute the inaccuracy or error in your Personal Information and have us correct the same within a reasonable period of time;
(4)Right to request for the suspension, withdrawal, blocking, removal, or destruction of your Personal Information from our filing system, in both live and back-up systems;
(5)Right to obtain from us a copy of your Personal Information and/or have the same transmitted from us to another entity, in an electronic or structured format that is commonly used and allows further use by you; and
(6)Right to be indemnified for any damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of your personal data, taking into account any violation of your rights and freedoms as data subject.

11.12 Vietnam

a.For Vietnamese inside and outside Vietnam, and other persons in Vietnam, you have the following rights as a data subject:
(1)Right to be informed

You have the right to be informed of the processing of your Personal Information, unless otherwise provided for by law.

(2)Right to give consent

You have the right to give consent to the processing of your Personal Information, except for the case provided for by law.

(3)Right to access Personal Information

You have the right to access your Personal Information in order to view, correct or request correction of your Personal Information, unless otherwise provided for by law.

(4)Right to withdraw consent

You have the right to withdraw your consent, unless otherwise provided by law.

(5)Right to delete Personal Information

You have the right to delete or request deletion of your Personal Information, unless otherwise provided for by law.

(6)Right to restrict of data processing

You have the right to request to restrict the processing of your Personal Information, unless otherwise provided for by the law.

The restriction on the processing of Personal Information shall be implemented with all Personal Information that you request the restriction within 72 hours after receiving your request, unless otherwise provided for by law.

(7)Right to data provision

You may request us to provide you with your Personal Information, unless otherwise provided by law.

(8)Right to object to data processing

You have the right to object to us processing your Personal Information in order to prevent or restrict the disclosure of Personal Information or the use of Personal Information for advertising and marketing purposes, unless otherwise provided for by law.

We shall comply with your request within 72 hours after receiving the request, unless otherwise provided for by law.

(9)Right to complain, denounce and initiate lawsuits

You have the right to lodge complaints, denunciations or initiate lawsuits in accordance with law.

(10)Right to claim damages
(11)You have the right to claim damages in accordance with the law when a violation of the provisions on the protection of Personal Information occurs, unless otherwise agreed between you and us or otherwise provided for by law.
(12)Right to self-protection

You have the right to self-protection in accordance with the provisions of the Vietnamese Civil Code (Law No. 91/2015/QH15, as amended or supplemented (if any)), other relevant laws and Decree No. 13/2023/ND-CP (as amended or supplemented (if any), “Decree 13”), or request competent agencies and organizations to take measures to protect civil rights as prescribed in Article 11 of the Vietnamese Civil Code.

b.For Vietnamese inside and outside Vietnam, and other persons in Vietnam, you may have the following obligations as a data subject:
(1)The obligation to protect your Personal Information and request other relevant organizations and individuals to protect your Personal Information;
(2)The obligation to respect and protect the Personal Information of others;
(3)The obligation to provide complete and accurate Personal Information when agreeing to allow the processing of Personal Information;
(4)The obligation to participate in propagating and disseminating skills to protect Personal Information; and
(5)The obligation to implement the provisions of the law on personal data protection and participate in preventing and combating violations of regulations on personal data protection.
c.We make efforts to keep your Personal Information in accurate and up-to-date condition, and take the necessary and appropriate security control measures in order to protect your Personal Information against undesirable adverse effects or damage that may occur in the process of our processing of your Personal Information, such as unauthorized access, tampering, leakage, loss, and damage.

Please be advised that it cannot be denied that Personal Information we collect might include your sensitive personal data defined under Decree 13.

11.13 Taiwan

a.We process your Personal Information based on your consent or in compliance with applicable laws and regulations.

11.14 New Zealand

a.In addition to the rights stated in Section 8.1, where you request the correction of Personal Information we hold about you, you have the right to request us to attach your statement of the correction to the original information that was requested to be corrected but not corrected.

11.15 Brazil

a.Article 18 of the General Personal Data Protection Law (Law 13.709/2018) (“LGPD”), grants you the following rights:
(1)Confirmation of the existence of Personal Information processing
(2)Access to Personal Information
(3)Correction of incomplete, inaccurate or outdated Personal Information
(4)Anonymisation, blocking or deletion of unnecessary, excessive or processed Personal Information that do not comply with the LGPD
(5)Portability of Personal Information to another service or product provider, upon express request, in accordance with the regulations of the National Data Protection Authority
(6)Withdrawal of consent and consequent disposal of Personal Information processed, except in the cases provided for in Article 16 of the LGPD
(7)Information of public and private entities with which the controller has made shared use of Personal Information
(8)Personal Information on the possibility of not providing consent and on the consequences of refusal
(9)Revocation of consent, pursuant to Section 5 of Article 8 of the LGPD
b.We appoint the data protection officer to protect your Personal Information, to collect your opinions and handle complaints about such information:

Contact: E-mail: privacy@lottejtb.com

Last Revised: March 31, 2026

Effective Date: May 1, 2026