The collector of user information (hereinafter referred to as "we" or "BUFFALO")
(1) Shanghai Weifu Supply Chain Management Co.
(2) Guangzhou Tui's Supply Chain Management Co;
(3) BUFFALO International Logistics.
China: Room 301, Building A, Lane 1156, Shenbin South Road, Shanghai
South Africa: Cnr Springbok & Jones Road, Bartlett, Boksburg, 1460
Tel: +86-400-921-9066 (China)
+27-105903190 (South Africa)
South Africa Contact: email@example.com
Chinese Contact: firstname.lastname@example.org
Terms and conditions
Your trust is very important to us, and we are aware of the importance of user information security. We will take security measures to protect your user information in accordance with legal and regulatory requirements. BUFFALO will not provide your personal information to third parties without your authorization.
For the purpose of this Agreement, "Personal Information" shall be as defined in the" Law of the People's Republic of China on the Protection of Personal Information". "Law of the People's Republic of China on the Protection of Personal Information" was adopted on 20 August 2021 and effective from 1 November 2021;
If you have any questions, comments or suggestions regarding the contents of this policy, you may contact us via the BUFFALO compliance email address (email@example.com/ firstname.lastname@example.org) or customer service telephone number (+86-400-921-9066 China / +27-105903190 South Africa)
This policy explains how BUFFALO collects, stores, protects, uses and provides information about you to the public and explains your rights, the main points of which are as follows:
1. to make it easier for you to understand the types of information we need to collect and what we use when you use our services, we will explain each of these in relation to the specific service you are using.
2. we will collect information about you that is lawful, legitimate and necessary for the purpose of providing our services to you.
3. If it is necessary to share your information with a third party in order to provide you with our services, we will assess the legality, legitimacy and necessity of the information collected by that third party. We will require the third party to take protective measures for your information and to comply with relevant laws and regulatory requirements. In addition, we will obtain your consent or confirm that the third party has obtained your consent in the form of a confirmation agreement, textual confirmation in specific cases, pop-ups, etc., as required by laws, regulations and national standards.
4.If we need to obtain information from a third party in order to provide services to you, we will require the third party to indicate the source of the information and to ensure the legality of the information provided by the third party; if we need to carry out personal information processing activities for our business beyond the scope of your original authorisation to provide personal information to the third party, we will obtain your explicit consent.
5.You can access and manage your information, cancel your account or report a complaint in the ways described in this policy.
You can read the appropriate sections of this policy for further details of the specific agreements in accordance with the following index:
I. How we collect information
III. How we store and protect information
IV. How we use information
V. How we provide information to the public
VI. Your rights
VII. Children's use of the website
VIII. Application and updates to this policy
I. How we collect your personal information
1. Explanation of terms
1) Personal information:
Personal information is all kinds of information recorded electronically or otherwise in relation to an identified or identifiable natural person, excluding information that has been anonymised and processed. We collect personal information including basic personal information (personal name, address, shipping address, personal phone number, email address), ID card number, user name, account password, workplace, express routing information, logistics bill number, precise positioning information, and transaction information.
(2) Sensitive personal information:
Sensitive personal information is personal information that, if leaked or used illegally, could easily lead to the infringement of a natural person's human dignity or endanger the safety of his or her person or property, including biometric, religious beliefs, specific identity, medical and health care, financial accounts, trajectory and other information, as well as the personal information of minors under the age of 14. Sensitive personal information covered by this policy will be highlighted in bold type. We collect sensitive personal information including ID numbers, telephone numbers, precise location information, transaction information, email addresses bank accounts.
3) Courier logistics services:
All service activities that occur from the time we receive a user's order until the item is delivered to the user, ensuring that the user's item is delivered on time and within the time requested by the customer, including services such as order placement, receipt, encapsulation, transit, delivery and after-sales.
4) Sending users
Individuals or organisations who obtain express logistics services from the express logistics service operator, including sending users and receiving users.
5) Express shipment routing information
The express logistics service operator records the information on the routing of express shipments in the main aspects of sending and delivery, and accordingly provides the users with the query information on express shipments, including the processing time, processing place, processing status and processing results, etc.
2. Scenarios where collection is necessary to achieve a business function
We may collect, store and use information about you in order to carry out the functions described below. If you do not provide the relevant information, you will not be able to access the relevant services. These functions include:
1) Shipping user registration
2) Necessary to provide logistics services
When you place a shipping order or your information is provided as a recipient, we, or through authorised business partners, collect the following information from you:
When you use our international shipping services, we collect the sender's and recipient's name (the recipient may be a name), address, contact details and the name, nature and quantity of the items to be shipped (collectively, "Waybill Information") for the purposes of order submission, logistics waybill generation, collection, sorting, storage, transportation and delivery of goods; in accordance with the According to the Measures for the Administration of Mail and Express Mail Receipt and Delivery by Real Name, the sender's valid identity document is checked at the time of receipt, relevant identity information is registered and a copy of the valid identity document is retained. If the sender is a legal person or other organization, the unified social credit code will be verified and recorded, and a copy of the valid identity document of the legal representative or the relevant person in charge will be retained. In accordance with the Measures of the Customs of the People's Republic of China for Supervision of Inbound and Outbound Express, we will also collect your identity document information (including the front and back of your ID card) for application to the Customs for import and export declaration procedures. In the event that data is required to leave the country in this business scenario, we will ensure that the data leaves the country in strict accordance with the provisions of this policy and will seek your consent separately. If we need to use the services of a third party to complete import/export declarations, we may ask the third party to process the information we have collected. We will also require the third party to take strict measures to protect the storage and use of your personal data from transfer, disclosure and leakage. In accordance with South African Customs policy (SC-CF-19 2.1), from 9 August 2018, we will require the recipient to provide an Importer's Code (South African Customs Import Code) or ID (South African local ID number) to complete the customs clearance process. ://www.buffaloex.com/importercode
When you use our shipping services within South Africa, we will collect
In addition, in the process of providing you with collection and delivery services, if telephone communication is involved, we may record the call to avoid potential disputes.
3) Payment settlement
After you have placed your order, you may choose the payment service provided by our affiliates or third-party payment institutions (such as Alipay and other payment channels such as UnionPay, Netflix and credit cards, hereinafter referred to as "payment institutions") with whom we need to provide your order number and transaction amount information to confirm your payment instruction and complete the payment.
If you are an enterprise user, you need to provide the following information when applying for invoices: invoice payable, taxpayer identification number, taxpayer email address and mobile phone number; if you are an individual/institution, you need to provide the following information: payable name, email address and mobile phone number.
4) Message push
When we use Whatsapp to push you information on shipment routing, payment status, promotional offers and other news notifications, we will collect your device model and operating system and version in order to complete the push function. You can set up a do-not-disturb setting on Whatsapp.
5) Customer service and after sales
To identify you, our call centre and online customer service will use your account information and invoice information to verify your identity. When you need us to provide customer service and after-sales service in relation to your shipment, we will check your waybill information and shipment routing information.
If you ask us to change your delivery address, contact person or phone number, you may be required to provide information other than the above when communicating with our customer service staff.
3. When we obtain your personal information from third parties
Where we obtain your personal information from our partners, we will use such personal information in accordance with our agreements with the third party and subject to the relevant laws and regulations.
We undertake to:
(1) The amount of your personal information that we obtain indirectly from third parties is the minimum amount necessary to carry out the business functions of the product.
(2) When we obtain your personal information indirectly from a third party, we will require the third party to indicate the source of the personal information and will confirm the legitimacy of the source of their personal information. We will understand and pay careful attention to the extent to which the third party has obtained your authorized consent to process your personal information including the purpose of use, whether you have authorized consent to transfer, share, publicly disclose, etc. If we need to process personal information beyond the scope of such authorization, we will obtain your express consent within a reasonable period of time after obtaining your personal information or before processing your personal information.
4. Exceptions to the requirement to obtain authorised consent
You are fully aware that we do not require your authorised consent for the collection and use of personal information in the following circumstances:
1) in connection with the performance of the obligations of the controller of personal information under laws and regulations
2) directly related to national security or defence security
3) directly related to public safety, public health, or significant public interest
4) directly related to criminal investigation, prosecution, trial and execution of judgments, etc;
5）for the purpose of safeguarding the life, property and other significant legitimate rights and interests of the subject of personal information or other individuals but where it is difficult to obtain his or her authorized consent
6) Where the personal information involved is disclosed to the public by the subject of the personal information himself/herself
7) where it is necessary for the conclusion and performance of a contract at the request of the subject of personal information
8) where personal information is collected from information that is lawfully and publicly disclosed, such as lawful news reports, government information disclosure and other channels
9) necessary to maintain the safe and stable operation of the products or services provided, such as the detection and disposal of faults in products or services
According to the law, the sharing or transfer of personal information that has been de-identified and ensures that the recipient of the data cannot recover and re-identify the subject of the personal information is not an act of external sharing, transfer and public disclosure of personal information, and the retention and processing of such data will not require separate notification to you and your consent.
2. Do Not Track
Many web browsers have a Do Not Track feature, which issues Do Not Track requests to websites. Currently, the major Internet standards organisations have not established policies that govern how websites should respond to such requests. However, if your browser has Do Not Track enabled, then all of our websites will respect your choice.
III. How we store and protect information
1. In principle, personal information collected and generated by us in the People's Republic of China will be stored in the territory in accordance with the requirements of applicable laws. When it comes to cross-border shipping operations, we will conduct a data exit security self-assessment and a personal information security impact assessment, evaluate the cross-border data transfer of personal information, and conduct the transfer on the premise that it is minimal and necessary to satisfy the shipping operations, and we will keep detailed logs of the cross-border transfer. Although there may be situations where the destination country of the information transfer differs, we will protect such information at a level of data protection no less than that of the country in which the personal information was originally collected.
We will keep information that forms part of our business records for at least five years. This is because we may need it in some way to support a claim or defence in court. It is also the period for which our taxing authorities may require to know about it.
2. How we protect the security of your personal information
(1) In order to keep your information secure, we will take all measures reasonably necessary to protect your information once we have collected it. For example, in a technology development environment, we will only use de-identified information for statistical analysis. We will store de-identified information separately from information that can be used to re-identify individuals to ensure that individuals are not re-identified in subsequent processing of de-identified information.
(2) We use industry standard security measures and technical solutions to prevent unauthorised access, use and alteration of your information and to avoid damage, loss or leakage of data, including but not limited to: in terms of physical security, we deploy monitoring systems and access control in strict accordance with the server room management system; in terms of technology, we provide application services using site-wide https transmission protocol and encrypted transmission using TLS/SSL certificates issued by authoritative CA institutions to ensure the confidentiality and integrity of data transmission.
(3) In terms of management, we regulate the storage and use of information and data by establishing a management system for classifying, labelling and disposing of information assets and guidelines for classifying and classifying information assets, and we conduct background checks, sign confidentiality agreements and conduct regular training and awareness-raising on information and privacy protection before all employees are hired.
(4) We have established a person and organization responsible for personal information protection to conduct personal information security impact assessments on the collection, use, sharing and entrusted handling of personal information. You can contact us in the following ways and we will respond to your request within 15 days:
a. Contact us through our customer service number +86-400-921-9066 China / +27-105903190 South Africa or "Online Customer Service", which will refer the relevant matters to the department responsible for personal information protection.
b. We continuously absorb and learn from domestic and international information security and privacy standards, we follow the requirements of international and domestic authoritative standards such as ISO/IEC27001 International Information Security Management System, ISO/IEC27701 International Privacy Information Management System, Information Security Level 3 Certification, etc. We also actively benchmark with domestic and international personal information and privacy protection laws and regulations, such as domestic Personal Information Security Standard GB/T35273, EU GDPR, to continuously improve the security of our products and/or services, enhance your user experience and safeguard your privacy.
(6) We will take all reasonably practicable steps to ensure that no unrelated personal information is collected. We will only retain your personal information for as long as is necessary for the purposes set out in this policy, unless we need to extend the retention period or are permitted to do so by law.
(7) We have a duty and obligation to remind you that the Internet is not an absolutely secure environment and we will endeavour to ensure the security of any information you send to us. Except in cases of force majeure, we will be liable for any breach of our physical, technical, or managerial safeguards that results in unauthorised access, public disclosure, tampering, or destruction of information, resulting in damage to your legal rights.
(8) Even if we have implemented strict protection measures, in the unfortunate event that personal information is leaked, we will promptly inform you, in accordance with the requirements of relevant laws and regulations, of the basic situation and possible impact of the leakage of personal information, the measures we have taken or will take to deal with it, the suggestions you can independently prevent and reduce the risk, and the remedial measures for you. At the same time, we will promptly inform you of the incident by email, letter, telephone, or push notification, etc. When it is difficult to inform the subjects whose information has been leaked one by one, we will take reasonable and effective ways to make announcements. We will also take the initiative to report on the handling of personal information leaks in accordance with the requirements of the regulatory authorities.
IV. How we use information
1. In order to comply with national laws, regulations and regulatory requirements, and to provide you with services and improve the quality of those services, or to protect the security of your account, we may use your information in the following circumstances:
a. for the purposes of conducting our business;
b. for the purpose of allowing access to our website and registering/subscribing/purchasing/using our services;
c. to allow access to and use of our mobile applications (if any) ("Apps");
d. for the purpose of fulfilling our legal obligations;
e. for the purposes that we make clear to you at the time of collecting your personal information; and
f. to verify your identity for security purposes:
g. For the marketing of our services and products;
2. When we want to use information for purposes other than those set out in this policy, we will ask for your consent again in the form of a confirmation agreement, scenario-specific textual confirmation actions, etc., as required by law, regulation and national standards.
V. How we provide information to the public
In certain circumstances, we may transfer your personal information to third parties, such as our service providers, group companies and law enforcement agencies. These circumstances include
a. We share your information with other members of our group of companies so that we can provide the best possible service within the group. They must store and use your information in accordance with the requirements of this statement.
b. We will share your personal information with analytics and search engine providers and obtain information from them to help us improve and optimise our websites and applications and to better personalise content and advertising.
c. We share your information with our authorised business partners, resellers, certain contractors or service providers (e.g. data processors). They may process your personal information for us, for example, if we use a cloud service provider (e.g. AliCloud). Other service providers include advertising agencies, IT providers, backup and disaster recovery specialists, email providers and outsourced call centres. Our suppliers and service providers will be required to meet our standards for handling information and security. The information we provide to them, including your information, will only be provided to them in the performance of their functions. They must not use your information for any purposes other than those described in this statement.
d. We may share your information with payment processors. When you place an order, you may select a BUFFALO related party or any third party payment provider with whom BUFFALO works (for payment services provided, we will provide your order number and transaction amount information to these payment providers to confirm your payment instructions and complete the payment.
2. In certain circumstances, your personal information may be transferred to other third-party organizations:
a. if we discuss the sale or transfer of part or all of our business - information may be transferred to a prospective buyer subject to appropriate confidentiality provisions;
b. if we restructure or sell - information may be transferred to a buyer who can continue to provide services to you;
c. if we are required to do so by law, or by any regulatory rules or practices we follow, or by any public or regulatory authority (such as the police or customs authorities);
d. if we defend against a legal claim, your information may be transferred in connection with that claim.
Your personal information may be shared if it is anonymised and aggregated, as in this case it will no longer be personal information.
VI. Your rights
You have certain rights in relation to your information. Some of these rights apply only in certain circumstances. If you wish to exercise or discuss these rights, please contact us at email@example.com.
a. Access: You have the right to check whether we are processing your information and, if so, you can request access to your personal information. You may receive a copy of the personal information we hold about you and certain other relevant information.
b. Correction: You have the right to request that we correct any incomplete or inaccurate personal information that we hold about you.
c. Erasure: In certain circumstances, you have the right to request that we delete or remove personal information. We may refuse a request for erasure in certain exceptional circumstances, for example, to comply with relevant legislation or to respond to relevant claims.
d. Restrictions: You have the right to request that we suspend the processing of certain personal information about you, for example, if you wish us to determine its accuracy or the reason for its processing.
e. Transfer: You may request that we transfer certain of your personal information to another party.
f. Objections: You may object when we process your personal information on the basis of our legitimate interests (or the interests of a third party). However, we may be entitled to continue to process your information on the basis of our legitimate interests or in connection with a legal claim. You also have the right to object if we process your personal information for direct marketing purposes.
g. Consent: If we process personal information on the basis of consent, you may withdraw your consent.
vii. children's use of the website