Samsung Pay Privacy Notice

Effective Date: [DATE]

Samsung Electronics Co., Ltd. (“Samsung”), along with our affiliates and subsidiaries, respect your concerns about privacy. This Samsung Pay Privacy Notice applies to the personal information we collect through the Samsung Pay services (“Samsung Pay). It does not apply to information collected by other apps, websites or services provided by Samsung. Samsung is the data controller for the processing of personal data.

This Privacy Notice provides information about how Samsung collects, uses and shares your personal information in connection with Samsung Pay. Our Privacy Policy at https://account.samsung.com/membership/pp (“Samsung Privacy Policy”) will also apply to your use of Samsung Pay, and should be read in conjunction with this Privacy Notice. In the event any portion of this Privacy Notice conflicts with the Samsung Privacy Policy, the relevant provisions of this Privacy Notice will apply.

WHAT INFORMATION DO WE COLLECT?

Through Samsung Pay, we obtain and maintain information about you in various ways.

Information You Provide Directly

Samsung Pay collects information from you directly. For example:

• When you create an account or profile with us, we may ask for information such as your Samsung Account ID and profile, name, or email address.

• If you order a product or paid service through Samsung Pay, we will ask for your name, address, contact information, and shipping and payment card information to process your order. Your payment card information is stored securely on your device. Samsung will only receive information about the country of issuance, which bank your card is associated with and whether your card is debit or credit. This information is stored by Samsung to ensure that your card is eligible for Samsung Pay, and may be used to tailor direct marketing messages you receive, but only where you have separately consented to receive direct marketing (and you may withdraw this consent
at any time).

Information About Your Use of Samsung Pay In addition to the information you provide, we will collect information about your use of our Samsung Pay through software on your devices and by other means. We will collect:

• Samsung Pay usage: The number of payment cards registered on Samsung Pay, recent transaction history, Samsung Pay Deals and Coupons viewed or redeemed, and use of Samsung Rewards. In addition, when you complete transactions through Samsung Pay we will collect information about such transactions, such as the type of payment technology used to initiate a payment transaction, whether and what time a payment transaction was attempted, the online merchant completing the transaction and transaction amount.

• Third-party device, app, service or program identifiers when you choose to connect such devices, apps, services or programs to Samsung Pay (such as issue (bank) loyalty or membership programs, or coupons, deals, discounts, tickets and/or vouchers), for example issuer name, card network, and card artwork.

• Device information: Your hardware model, device hardware information, IMEI number, advertising identifiers (including Google Ad ID and Android ID), other unique device identifiers (such as IP address and GUID), serial number, device settings (including language and lock settings), device status information (including connections with other devices), current app, software and operating system version, country and network codes and MAC address. In addition, we may obtain information about how, when and for how long you use your Samsung Pay-enabled devices, including your
usage of Samsung Pay and Samsung and third-party apps, services or programs on the devices (such as apps and themes download and purchase information and marketing push information).

• Location information: Your device’s GPS signal or information about nearby Wi-Fi access points and cell towers that may be transmitted to us when you use Samsung Pay.

HOW DO WE USE YOUR INFORMATION?

We use the information we collect for the following purposes:

• To help you or your device register for Samsung Pay.

• To provide Samsung Pay or a feature you request.

• To provide customized content and personalized services based on your past activities on Samsung Pay.

• To provide customized advertising, tailored direct marketing, promotions, banners and offers that might interest you, but only where you have given us your separate consent to do so, and you may withdraw this consent at any time.

• To analyze Samsung Pay to help us better understand our customers in order to offer make it more convenient and useful.

• To provide software updates, maintenance services and support for Samsung Pay.

• To comply with the law and legal processes.

• To protect the rights, property, or safety of Samsung Electronics, or any of our affiliates, business partners, or customers.

We use and combine the information we collect about you from Samsung Pay with data from other services or features you use. For example, if you choose to save your payment card information with another Samsung service (including, without limitation, Samsung Internet or Samsung Billing), Samsung will ask user whether they want to save or send that card information to Samsung Pay to enroll with the service.

Samsung processes personal information for the purposes described above. Where required by applicable law, Samsung’s legal basis to process personal information includes processing:

(i) So that we can fulfil our contractual obligations to you, such as providing you with Samsung Pay;

(ii) To pursue to our legitimate interests, for example, to promote our business and manage our relationship with you;

(iii) To comply with applicable laws and legal processes; and

(iv) With your separate consent, where necessary (for example, to send direct marketing communications related to Samsung Pay). For information relating to consent to direct marketing communications informed by your transactions with your Samsung Pay Card, please see the section headed: “Partnership with Curve” below.

If you give consent by ticking a checkbox when you first sign up for Samsung Pay, you can always revoke it by clicking the Settings icon on the Samsung Pay app (on the Settings screen next to “Marketing information” simply click on the on/off tab) or by contacting us as specified in the CONTACT US section below.

Third-Party Analytics

o Through certain services, we may collect personal information about your online activities on websites and connected devices over time and across third-party websites, devices, apps, and other online features and services. We may use thirdparty analytics services on Samsung Pay, such as those of Google Analytics. The service providers that administer these analytics services help us to analyse your use of Samsung Pay and improve Samsung Pay. The information we obtain may be disclosed to or collected directly by these providers and other relevant third parties who use the information, for example, to evaluate use of Samsung Pay, help administer Samsung Pay, and diagnose technical issues. To learn more about Google Analytics, please visit: https://support.google.com/analytics/answer/6004245 and https://www.google.com/policies/privacy/partners.

WHO DO WE SHARE YOUR INFORMATION WITH?

We will disclose your information internally within our business, but only to those who need it to further provide services or to help with your requests.

We will also disclose your information to the following entities, only to the extent that this will be necessary to provide our services:

Affiliates: Other Samsung Electronics Group companies which we control or own.

Business Partners: Partners who we work together with to provide you Samsung Pay. For example, we may work with a bank so that you can use one of our services to make faster and more efficient payments. These business partners control and manage your personal information.

Service Providers: Carefully selected companies that provide services for or on behalf of us, such as companies that help us with repairs, customer contact centres, customer care activities, advertising (including customised advertising on our websites, thirdparty websites, or online platforms), conducting customer satisfaction surveys, or billing, or that send emails on our behalf. These providers are also committed to protecting your information.

Other Parties when Required by Law or as Necessary to Protect Our Services: For example, it may be necessary by law, legal process, or court order from governmental authorities to disclose your information. They may also seek your information from us for the purposes of law enforcement, national security, anti-terrorism, or other issues that are related to public security.

Other Parties in Connection with Corporate Transactions: We may disclose your information to a third party as part of a merger or transfer, acquisition or sale, or in the event of a bankruptcy.

Other Parties with Your Consent or at Your Direction: In addition to the disclosures described in this Privacy Policy, we may share information about you with third parties when you separately consent to or request such sharing.

Partnership with Curve

To ensure Samsung Pay is made available to as many customers as possible, Samsung has partnered with payment card aggregator Curve to facilitate a connection with payment issuers who would otherwise not be compatible with Samsung Pay (and which can be accessed by use of a Samsung universal payment card, the “Samsung Pay Card”). As a Business Partner with whom Samsung works to provide the Samsung Pay Card, Curve controls and manages certain personal information you provide directly. When enrolling a payment card on Samsung Pay Card via Curve, Samsung Pay users may also give consent for Curve to share certain personal information with Samsung (e.g., user profiles based on transaction history) to inform marketing materials sent by Samsung to those users. Samsung Pay Card users can withdraw consent to the use of their personal information for marketing purposes and related data processing at any time by selecting the “unsubscribe” button at the bottom of any marketing communication, or by visiting the Samsung Pay Card FAQs [LINK] where an unsubscribe link can be found, or by contacting us as specified in the CONTACT US section below.

HOW DO WE KEEP YOUR INFORMATION SECURE?

We take data protection seriously. We’ve put in place physical and technical safeguards to keep the information we collect secure. However, please note that although we take reasonable steps to protect your information, no website, Internet transmission, computer system, or wireless connection is completely secure.

WHERE DO WE SEND YOUR DATA?

Your use of Samsung Pay will involve the transfer, storage, and processing of your personal information within and outside of your country of residence, consistent with this policy. In particular, your personal information will be transferred to the Republic of Korea. Please note that the data protection and other laws of countries to which your information may be transferred might not be as comprehensive as those in your
country.

[For European Economic Area (EEA) Residents Only]

In addition, your use of Samsung Pay may also involve the transfer, storage, and processing of your personal information to other countries; such countries include, without limitation, countries in the European Economic Area, the United States of America, China, Singapore, Vietnam, India, Canada, the Philippines, and Japan. We will take appropriate measures, in compliance with applicable law, to ensure that your personal information remains protected. Such measures include the use of Standard Contractual Clauses to safeguard the transfer of data outside of the EEA. To request more information or to obtain a copy of the contractual agreements in place, contact us. See the CONTACT US section below.

WHAT ARE YOUR RIGHTS?

Your personal information belongs to you. You can ask us to provide details about what we’ve collected, and you can ask us to delete it or correct any inaccuracies. You can also ask us to restrict or limit processing, sharing, or transfer of your personal information, as well as to provide to you your personal information that we’ve collected so you can use it for your own purposes. However, requesting the deletion of your personal information may also result in a loss of access to services we provide. We won’t delete data that we’re required by law to retain.

To make a request concerning your rights or to make an inquiry, see the CONTACT US section below.

HOW LONG DO WE RETAIN YOUR INFORMATION AND WHERE DOES IT GO?

We will not keep your personal data for longer than is necessary for the purpose for which it was collected. This means that information will be destroyed or erased from our systems when it is no longer required. We encrypt and securely retain the following types of data about you according to the table below:

Data type

Retention period

Destruction period/process

Account and contact information

(i) For as long as necessary to help you or your device register for and use Samsung Pay, or (ii) Upon user’s request for deletion, or (iii) deletion of Samsung Pay account, whichever comes first.

Subject to applicable law, deleted immediately upon the expiry of the retention period.

Samsung Pay usage

(i) For as long as necessary to provide Samsung Pay or a feature you request, including without limitation to provide customized content and personalized services based on your past activities on Samsung Pay, analyze Samsung Pay to help us better understand our customers in order to offer make it more convenient and useful, or (ii) upon user’s request for deletion, or (iii) deletion of Samsung Pay account, whichever comes first.

Subject to applicable law, deleted immediately upon the expiry of the retention period.

Third-party identifier information

(i) For as long as necessary to provide customized advertising, tailored direct marketing, promotions, banners and offers that might interest you, only where you have given us your separate consent, or (ii) upon user’s request for deletion, or (iii) deletion of Samsung Pay account, whichever comes first.

Subject to applicable law, deleted immediately upon the expiry of the retention period.

Device information

(i) For as long as necessary to provide software updates, maintenance services and support for Samsung Pay, or (ii) upon user’s request for deletion, or (iii) deletion of Samsung Pay account, whichever comes first.

Subject to applicable law, deleted immediately upon the expiry of the retention period.

Your use of Samsung Pay will involve the transfer, storage, and processing of your personal information to other countries outside of the European Union; such countries include, without limitation the United States of America, Republic of Korea and Singapore.

CONTACT US

You can contact us to update your preferences, correct your information, submit a request, or ask us questions. The easiest way is through the Contact Us section of https://www.samsung.com .

You can also contact us at:

Data Controller
Samsung Electronics Co., Ltd.
129, Samsung-ro, Yeongtong-gu,
Suwon-si, Gyeonggi-do 16677, Republic of Korea

[For European Economic Area (EEA) Residents Only]

Samsung Electronics has offices across Europe, so we can ensure that your request or query will be handled by the data protection team based in your region.

The easiest way to contact us is through our Privacy Support page
at https://www.samsung.com/request-desk .

You can also contact us at:

European Data Protection Office
Samsung Electronics (UK) Limited
Samsung House, 1000 Hillswood Drive
Chertsey, Surrey KT16 0PS

You can lodge a complaint with the relevant supervisory authority if you consider that our processing of your personal information infringes applicable law. Contact details for all EU supervisory authorities can be found at https://edpb.europa.eu/aboutedpb/board/members_en .

UPDATES TO THIS PRIVACY NOTICE

This Privacy Notice may be updated periodically to reflect changes in our personal information practices with respect to Samsung Pay or changes in the applicable law. We will indicate at the top of this Privacy Notice when it was most recently updated. If we update the Privacy Notice, we will let you know in advance about changes we consider to be material by placing a notice on relevant services or by emailing you, where appropriate.