Last updated: March 25, 2026 — Effective immediately upon publication.
This Privacy Policy explains how Buffalo.it.com ("we," "us," or "our") collects, uses, and protects the personal information you provide when visiting our website or engaging with our wholesale services.
When you submit an enquiry, open a wholesale account, or contact us, we may collect your name and surname, business name and registration details, email address and phone number, shipping and billing addresses, purchase history and order data, and payment information (processed securely via our payment partners).
When you visit buffalo.it.com, our servers and analytics tools may automatically collect your IP address, browser type and version, operating system, referring URL, pages visited and time spent, and cookie identifiers.
We use strictly necessary cookies to maintain session state, functional cookies to remember your preferences, and analytics cookies to understand how visitors use our site. You may disable non-essential cookies via your browser settings. This will not affect your ability to view our content, but may limit some interactive features.
We use collected information to process and fulfil wholesale orders, respond to enquiries and support requests, manage your wholesale account, send order confirmations, invoices, and shipping notifications, improve our website and service quality, comply with legal and regulatory obligations, and detect and prevent fraud or security incidents.
We do not sell your personal data to third parties. We do not use your data for unsolicited marketing without your explicit consent.
We process your personal data on the following legal bases: performance of a contract (wholesale agreements, order fulfilment), legitimate interests (website security, fraud prevention, service improvement), legal obligation (tax, food safety, export compliance records), and consent (marketing communications, non-essential cookies).
We may share your information with trusted third-party service providers who assist us in operating our business, including logistics and cold-chain delivery partners, payment processing services (including Xaman for digital payments), IT hosting and cloud infrastructure providers, legal and compliance advisors, and government or regulatory bodies where required by law.
All third-party processors are contractually bound to handle your data in accordance with applicable data protection law.
Given the global nature of our wholesale operations, your data may be transferred to and processed in countries outside your country of residence. We ensure that such transfers are protected by appropriate safeguards, including standard contractual clauses or equivalent mechanisms recognised under applicable law.
We retain personal data only as long as necessary for the purpose for which it was collected. Order and financial records are retained for a minimum of seven (7) years to comply with tax and accounting obligations. Marketing consent records are retained until you withdraw consent. Website usage data is retained for up to 26 months.
Depending on your jurisdiction, you may have the following rights regarding your personal data: the right to access a copy of your data, the right to rectify inaccurate data, the right to erasure ("right to be forgotten"), the right to restrict or object to processing, the right to data portability, and the right to withdraw consent at any time.
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include TLS encryption for data in transit, access controls and role-based permissions, regular security reviews, and employee data protection training.
No transmission over the internet is 100% secure. While we take every reasonable precaution, we cannot guarantee absolute security.
Our website and services are directed exclusively at businesses and adult professionals. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our business practices. The updated version will be published on this page with a revised effective date. We encourage you to review this policy periodically.
For any questions about this Privacy Policy or how we handle your data, please contact:
Data Privacy Team — Buffalo.it.com
Email: [email protected]
Website: buffalo.it.com