개인정보처리방침
ITALIA EUGEN TRAVEL S.R.L.(이하 "회사")는 「개인정보 보호법」 및 EU 일반개인정보보호규정(GDPR) 등 관련 법령을 준수하며, 정보주체의 개인정보를 보호하고 관련 고충을 신속하게 처리하기 위하여 다음과 같이 개인정보처리방침을 수립·공개합니다.
1. 개인정보처리자
- 상호: ITALIA EUGEN TRAVEL S.R.L. (이탈리아 유진트래블)
- 대표: 김현기 · P.IVA: 16639521000
- 주소: Via Marcello Gallian 54, 00133 Roma, Italia
- 연락처: [email protected] · 070-8098-3946
2. 개인정보의 처리 목적
회사는 다음 목적을 위하여 개인정보를 처리하며, 목적 이외의 용도로는 이용하지 않습니다. 목적이 변경되는 경우 관련 법령에 따라 별도의 동의를 받는 등 필요한 조치를 이행합니다.
- B2B 회원 가입 및 관리: 여행사·기업·단체 회원 자격 확인, 가입 승인, 본인 식별, 계정 관리, 비밀번호 재설정
- 견적 요청 응대: 견적 산출, 상담 및 결과 안내, 행사 진행을 위한 연락
- 서비스 운영: 이탈리아 소식 등 회원 대상 정보 제공, 공지사항 전달, 문의 응대
3. 처리하는 개인정보 항목
- 회원 가입(필수): 회원 유형(국내여행사/국외여행사/기업·단체), 회사명, 사업자등록번호, 담당자 이름, 연락처, 이메일, 아이디, 비밀번호
- 회원 가입(선택): 관광사업자 등록번호, 직책, 요청 사항/메모
- 견적 요청: 회사명, 담당자명, 이메일, 연락처, 행사명, 예상 인원, 출발일·종료일, 주요 도시, 요청 서비스, 요청 상세 내용, 첨부파일(선택)
- 서비스 이용 과정에서 자동 생성: 접속 IP 주소, 접속 일시, 브라우저 정보 등 접속 기록(보안 및 서비스 안정성 확보 목적)
비밀번호는 복호화할 수 없는 방식으로 암호화되어 저장되며, 회사도 그 내용을 알 수 없습니다.
4. 개인정보의 처리 및 보유 기간
- 회원 정보: 회원 탈퇴 시까지. 가입이 거절된 경우 거절 후 지체 없이 파기합니다.
- 견적 요청 정보 및 첨부파일: 상담 종료 후 3년. 다만 계약이 체결된 경우 이탈리아 민법 등 관련 법령이 정한 거래 기록 보존 기간 동안 보관합니다.
- 접속 기록: 수집일로부터 최대 1년
회원이 탈퇴하더라도 위 기간 내의 견적 기록은 회원 계정과 분리된 상태로 보관될 수 있습니다.
5. 개인정보의 제3자 제공
회사는 정보주체의 개인정보를 제3자에게 제공하지 않습니다. 다만 정보주체가 별도로 동의한 경우 또는 법령에 특별한 규정이 있는 경우에는 예외로 합니다. 견적에 따른 현지 수배 과정에서 호텔·차량·가이드 등 협력업체에 정보 제공이 필요한 경우에는 사전에 별도로 안내하고 동의를 받습니다.
6. 개인정보 처리의 위탁 및 국외 이전
회사는 원활한 서비스 제공을 위하여 다음과 같이 개인정보 처리 업무를 위탁하고 있으며, 이 과정에서 개인정보가 국외에 저장·처리될 수 있습니다.
| 수탁자 | 위탁 업무 | 처리 국가 |
|---|---|---|
| Supabase, Inc. | 회원 계정·인증, 데이터베이스, 첨부파일 저장 | 대한민국(서울 리전) |
| Cloudflare, Inc. | 웹사이트 호스팅, 보안(접속 기록), 문의 메일 전달 | 미국 및 전 세계 데이터센터 |
| Resend | 비밀번호 재설정 등 안내 메일 발송 | 미국 |
| Microsoft Corporation (Outlook.com) | 문의 메일 수신·보관 | 미국 등 |
개인정보는 서비스 이용 시점에 정보통신망을 통해 위 국가로 전송되며, 보유 기간은 제4조와 같습니다. 회사는 위탁 계약 시 관련 법령에 따라 개인정보가 안전하게 관리되도록 필요한 사항을 규정하고 수탁자를 관리·감독합니다. 국외 이전을 원하지 않으시는 경우 회원 가입 및 견적 요청을 하지 않으실 수 있으나, 이 경우 해당 서비스 이용이 제한됩니다.
7. 개인정보 처리의 법적 근거 (EU GDPR)
- 회원 가입·관리 및 견적 응대: 계약의 체결 및 이행을 위한 처리 (GDPR 제6조 제1항 (b))
- 견적 상담을 위한 개인정보 수집·이용: 정보주체의 동의 (GDPR 제6조 제1항 (a))
- 보안 및 서비스 안정성을 위한 접속 기록: 회사의 정당한 이익 (GDPR 제6조 제1항 (f))
- 거래 기록 보존: 법적 의무의 이행 (GDPR 제6조 제1항 (c))
8. 개인정보의 파기 절차 및 방법
보유 기간이 지나거나 처리 목적이 달성된 개인정보는 지체 없이 파기합니다. 전자적 파일은 복구할 수 없는 방법으로 삭제하며, 종이 문서는 분쇄하거나 소각합니다. 다른 법령에 따라 보존해야 하는 경우에는 별도로 분리하여 보관합니다.
9. 정보주체의 권리와 행사 방법
정보주체는 언제든지 자신의 개인정보에 대하여 열람, 정정, 삭제, 처리정지, 동의 철회를 요구할 수 있으며, EU GDPR에 따라 개인정보 이동권 및 처리에 대한 이의제기권도 행사할 수 있습니다. 권리 행사는 아래 개인정보 보호책임자에게 이메일 또는 전화로 요청하시면 되며, 회사는 지체 없이(늦어도 1개월 이내) 조치하겠습니다. 동의를 철회하더라도 철회 이전에 이루어진 처리의 적법성에는 영향을 미치지 않습니다.
10. 개인정보의 안전성 확보 조치
- 비밀번호 일방향 암호화 저장 및 전 구간 암호화 통신(HTTPS)
- 데이터베이스 접근 권한을 회원 본인과 관리자로 엄격히 제한
- 첨부파일 및 게시판 이미지를 비공개 저장소에 보관하고, 권한 있는 사용자에게만 시간이 제한된 주소로 제공
- 관리자 계정 최소화 및 접근 기록 관리
11. 쿠키 및 브라우저 저장소의 사용
회사는 광고나 이용 행태 분석을 위한 쿠키를 사용하지 않습니다. 로그인 상태 유지와 언어 설정(한국어/영어)을 위해 이용자의 브라우저 저장소(localStorage)를 사용하며, 웹사이트 보안을 위해 호스팅 업체(Cloudflare)가 필수 보안 쿠키를 설정할 수 있습니다. 브라우저 설정에서 이를 삭제할 수 있으나, 이 경우 로그인 상태가 해제될 수 있습니다.
12. 만 14세 미만 아동의 개인정보
본 서비스는 여행사 및 기업·단체를 대상으로 하는 B2B 서비스로, 만 14세 미만 아동의 개인정보를 수집하지 않습니다.
13. 개인정보 보호책임자
- 성명: 김현기 (대표)
- 이메일: [email protected]
- 전화: 070-8098-3946
14. 권익 침해 구제 방법
개인정보 침해에 대한 신고나 상담이 필요하신 경우 아래 기관에 문의하실 수 있습니다.
- 개인정보침해신고센터: (국번 없이) 118 · privacy.kisa.or.kr
- 개인정보분쟁조정위원회: 1833-6972 · www.kopico.go.kr
- 이탈리아 개인정보 감독기관(Garante per la protezione dei dati personali): www.garanteprivacy.it
15. 개인정보처리방침의 변경
이 개인정보처리방침은 2026년 10월 3일부터 적용됩니다. 내용이 변경되는 경우 시행 7일 전부터 웹사이트를 통해 공지합니다.
ITALIA EUGEN TRAVEL S.R.L. (the "Company") complies with the EU General Data Protection Regulation (GDPR), the Korean Personal Information Protection Act and other applicable laws, and establishes and publishes this Privacy Policy to protect personal data and promptly handle related inquiries.
1. Data Controller
- Company: ITALIA EUGEN TRAVEL S.R.L.
- Legal Representative: KIM Hyonkee · P.IVA: 16639521000
- Address: Via Marcello Gallian 54, 00133 Roma, Italia
- Contact: [email protected] · +82 70-8098-3946
2. Purposes of Processing
- B2B membership: verifying the eligibility of travel agencies, companies and groups, approving registrations, identifying users, managing accounts and password resets
- Quote requests: preparing quotes, consultation, and communication needed to operate programs
- Service operation: providing Italy updates to members, sending notices, and responding to inquiries
3. Personal Data We Process
- Registration (required): member type (Korean travel agency / overseas travel agency / company or group), company name, business registration number, contact name, phone, email, username, password
- Registration (optional): tourism business license number, position, notes
- Quote requests: company name, contact name, email, phone, program name, estimated headcount, start/end dates, main cities, requested services, request details, attachments (optional)
- Generated automatically: access logs such as IP address, access time and browser information (for security and service stability)
Passwords are stored using irreversible encryption and cannot be read by the Company.
4. Retention Period
- Member data: until the account is deleted. If a registration is declined, the data is deleted without delay.
- Quote data and attachments: 3 years after the consultation ends, or, where a contract is concluded, for the record-keeping period required by Italian law.
- Access logs: up to 1 year from collection.
Quote records within these periods may be kept separately from the member account even after the account is deleted.
5. Disclosure to Third Parties
We do not disclose personal data to third parties except with your separate consent or where required by law. If information must be shared with local suppliers (hotels, transport, guides) to arrange a program, we will inform you and obtain your consent in advance.
6. Processors and International Transfers
| Processor | Service | Location |
|---|---|---|
| Supabase, Inc. | Accounts and authentication, database, file storage | Republic of Korea (Seoul region) |
| Cloudflare, Inc. | Website hosting, security (access logs), inquiry email forwarding | United States and global data centers |
| Resend | Service emails such as password resets | United States |
| Microsoft Corporation (Outlook.com) | Receiving and storing inquiry emails | United States and others |
Data is transferred over the network when you use the service and is retained as described in Section 4. Transfers outside the EU rely on adequacy decisions (e.g., the Republic of Korea) or other safeguards permitted under GDPR, and processors are bound by data processing agreements.
7. Legal Basis (GDPR)
- Membership and quote handling: performance of a contract (Art. 6(1)(b))
- Collection of data for quote consultation: consent (Art. 6(1)(a))
- Access logs for security: legitimate interests (Art. 6(1)(f))
- Retention of transaction records: legal obligation (Art. 6(1)(c))
8. Deletion
Personal data is deleted without delay once the retention period expires or the purpose is fulfilled. Electronic files are deleted irreversibly and paper documents are shredded. Data that must be retained under other laws is stored separately.
9. Your Rights
You may request access, rectification, erasure, restriction of processing, data portability, or object to processing, and you may withdraw consent at any time (without affecting the lawfulness of prior processing). Please contact the person in charge below; we will respond without undue delay and within one month.
10. Security Measures
- One-way encrypted passwords and encrypted connections (HTTPS) throughout
- Database access strictly limited to the member concerned and administrators
- Attachments and board images kept in private storage and served only to authorized users through time-limited links
- Minimal administrator accounts and access control
11. Cookies and Browser Storage
We do not use advertising or analytics cookies. We use your browser's local storage to keep you signed in and to remember your language, and our hosting provider (Cloudflare) may set strictly necessary security cookies. You can clear these in your browser settings, which may sign you out.
12. Children
This is a B2B service for travel agencies, companies and groups, and we do not collect personal data from children.
13. Person in Charge of Data Protection
- Name: KIM Hyonkee (Legal Representative)
- Email: [email protected]
- Phone: +82 70-8098-3946
14. Complaints
You have the right to lodge a complaint with a supervisory authority, in particular the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it), or, in Korea, the Personal Information Infringement Report Center (118, privacy.kisa.or.kr).
15. Changes to This Policy
This Privacy Policy applies from 3 October 2026. Any changes will be announced on this website at least 7 days before they take effect.