Legal & Compliance

Privacy Policy

This policy explains how Buhotec International LLC collects, uses, protects, and shares your personal and business information in connection with our wholesale electronics platform.

Effective January 1, 2026 GDPR CCPA LGPD OFAC / BSA
Table of Contents

Notice: This Privacy Policy is provided for informational purposes and represents Buhotec's current data practices. While this document reflects applicable legal requirements, it is not a substitute for independent legal advice. We recommend consulting qualified counsel regarding your specific compliance obligations.

1. Introduction

Buhotec International LLC ("Buhotec," "we," "us," or "our") is a wholesale-only consumer electronics distributor incorporated under the laws of the State of Florida, United States, with its principal place of business at 10900 NW 21st St, Unit 110, Doral, FL 33172. We serve registered business buyers across the United States and Latin America, including importers, distributors, and commercial resellers.

This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information and business data when you visit or use buhotec.com and all its subdomains (collectively, the "Platform"), apply for a wholesale account, communicate with our team, or otherwise interact with our services.

This Policy applies to all individuals whose personal data we process in connection with our business, including authorized representatives of prospective and current wholesale buyers, company officers and beneficial owners identified during our Know Your Customer ("KYC") process, and visitors to our website.

By registering for a wholesale account, using our Platform, or submitting information to us, you acknowledge that you have read and understood this Privacy Policy. If you are providing personal information on behalf of your organization, you represent that you have authority to do so and that you have informed the relevant individuals about our data practices.

This service is exclusively for businesses. We do not transact with or market to individual consumers. If you are an individual seeking consumer electronics, this Platform is not intended for you.

2. Data We Collect

We collect personal and business information in the categories described below. We collect only what is necessary for the purposes identified in Section 3 and for our legal compliance obligations.

2a. Business Registration Data

When you apply to become a wholesale buyer, we collect information about your organization, including:

  • Legal company name and any trade names or DBA names
  • Federal Tax Identification Number (EIN), VAT number, or equivalent tax registration number for your jurisdiction
  • Registered business address and principal place of business
  • Country and jurisdiction of incorporation or registration
  • Business license numbers and relevant trade permits
  • Nature of business, industry sector, and primary product categories
  • Estimated annual purchase volume and intended use of products
  • US resale tax exemption certificates (for US-based buyers)

2b. Personal Contact Information

We collect personal information about authorized representatives, legal signatories, and account contacts of your organization, including:

  • Full legal name
  • Job title and role within the organization
  • Business email address
  • Business and mobile telephone numbers
  • Business mailing address (where different from the company address)

2c. Compliance, KYC, and AML Data

As a wholesale distributor subject to US federal anti-money laundering ("AML") regulations, the Bank Secrecy Act ("BSA"), and the Office of Foreign Assets Control ("OFAC") regulations under 31 CFR Part 501, we are required by law to collect and retain certain compliance-related information. This includes:

  • Copies of government-issued photo identification documents for authorized representatives and legal signatories (e.g., passport, national ID, driver's license)
  • Beneficial ownership information for companies with 25% or greater ownership interests, including names, dates of birth, and identification documents of beneficial owners
  • Corporate formation documents (articles of incorporation, operating agreements, certificates of good standing)
  • AML screening results and risk-assessment records maintained in connection with our Customer Due Diligence ("CDD") obligations
  • OFAC Specially Designated Nationals ("SDN") check records, including the date, result, and data source of each screening
  • Ongoing transaction monitoring records
  • Records of any Suspicious Activity Reports ("SARs") or Currency Transaction Reports ("CTRs") filed, as required by law (we are prohibited from disclosing the existence of such filings to any person other than authorized regulatory or law enforcement authorities)

Why we collect this: Collection of KYC and AML data is not optional. It is a mandatory legal obligation under the Bank Secrecy Act (31 U.S.C. § 5311 et seq.), FinCEN regulations (31 CFR Chapter X), and applicable OFAC sanctions programs. Failure to provide this information will prevent us from opening or maintaining a wholesale account.

2d. Transaction and Order Data

When you place orders or transact with us, we collect and retain records including:

  • Order numbers, purchase orders, and invoice records
  • Products ordered, quantities, unit prices, and total amounts
  • Shipping addresses and delivery instructions
  • Payment method type and payment references (e.g., wire transfer reference numbers, ACH confirmation numbers)
  • Account statements and credit terms documentation
  • Correspondence and communications related to specific transactions

We do not collect or store credit card numbers, debit card numbers, or full bank account numbers. Payments are processed via bank wire transfer or ACH, and payment reference identifiers are retained for recordkeeping purposes only.

2e. Technical and Website Usage Data

When you visit buhotec.com or any of its subdomains, our infrastructure — including Cloudflare's content delivery network ("CDN") — automatically collects certain technical information, including:

  • IP address and approximate geolocation (country/region level)
  • Browser type, version, and rendering engine
  • Operating system and device type
  • Pages visited, referring URLs, and navigation paths
  • Session duration and interaction timestamps
  • HTTP request headers and response codes

This data is collected through Cloudflare's standard CDN and security infrastructure. We use Cloudflare to serve our website and to protect against distributed denial-of-service (DDoS) attacks, bot traffic, and other network-level threats. Cloudflare's privacy practices are governed by Cloudflare's Privacy Policy at cloudflare.com/privacypolicy.

3. How We Use Your Data

We use the personal and business information we collect for the following purposes:

Account Registration and Onboarding

To evaluate wholesale account applications, verify business legitimacy, establish your account in our systems, and communicate your approval status and account credentials.

Order Processing and Fulfillment

To process purchase orders, generate invoices, arrange shipping and logistics, track delivery status, and manage account-level pricing and payment terms.

AML, KYC, and OFAC Compliance (Mandatory)

To conduct mandatory customer due diligence as required by the Bank Secrecy Act, FinCEN regulations, and OFAC sanctions programs. This includes screening all customers and beneficial owners against OFAC's SDN List and other applicable sanctions lists prior to account approval and on an ongoing basis, maintaining required records, and filing required regulatory reports. This processing is not optional and cannot be refused without affecting your ability to transact with us.

Account Management and Customer Service

To manage your active wholesale account, respond to inquiries, resolve disputes, communicate product availability and pricing updates, and provide support related to your orders and account.

Fraud Prevention and Security

To detect, investigate, and prevent fraudulent transactions, unauthorized access, and other illegal activity in connection with our services. This includes monitoring unusual transaction patterns and verifying the authenticity of submitted documents.

Product and Catalog Recommendations

To provide you with relevant information about new products, promotions, and inventory updates based on your purchase history and expressed product interests. You may opt out of commercial communications at any time by contacting us at [email protected].

Legal Obligations and Regulatory Reporting

To comply with applicable US and international laws, respond to lawful requests from law enforcement or regulatory authorities (including FinCEN, OFAC, and applicable courts), and to protect the rights and interests of Buhotec and third parties.

Business Analytics and Platform Improvement

To understand how our Platform is used, identify technical issues, and make improvements. Technical usage data is used in aggregate and is not used to build personal profiles for advertising purposes.

For individuals in the European Economic Area ("EEA"), the United Kingdom ("UK"), or other jurisdictions where a legal basis for personal data processing must be identified under applicable law (including EU Regulation 2016/679, the "GDPR"), we rely on the following legal bases:

Contractual Necessity (Art. 6(1)(b) GDPR)

Processing of business registration data, personal contact information, and transaction data is necessary for the performance of a contract with you or your organization, or to take steps at your request prior to entering into a contract. Without this processing, we cannot establish or maintain a wholesale account relationship.

Legal Obligation (Art. 6(1)(c) GDPR)

Processing of KYC documentation, beneficial ownership records, AML screening results, and OFAC check records is necessary for compliance with our legal obligations under US federal law (the Bank Secrecy Act, 31 CFR Chapter X, and OFAC regulations under 31 CFR Part 501). These obligations apply to us regardless of the location of our customers. Additionally, we may be required to retain financial and transaction records under US tax law (26 U.S.C.) and applicable state laws.

Legitimate Interests (Art. 6(1)(f) GDPR)

We process technical and usage data and conduct fraud prevention activities on the basis of our legitimate interests in operating a secure, functional, and lawful wholesale business. We have assessed that these interests are not overridden by the rights and interests of the individuals concerned, given the B2B nature of our services and the limited intrusiveness of the processing involved.

Consent (Art. 6(1)(a) GDPR)

Where we rely on consent — for example, for optional commercial communications — you have the right to withdraw consent at any time by contacting us at [email protected]. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal, and does not affect processing carried out on other legal bases.

5. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information to any third party for marketing or commercial purposes.

We share personal and business data only in the limited circumstances described below:

5a. Supabase Inc. (Database Processor)

Our platform's database infrastructure is operated by Supabase, Inc., a US-based company. All account data, KYC records, and transaction data are stored in a PostgreSQL database hosted via Supabase on Amazon Web Services (AWS) infrastructure in the us-east-1 region (Northern Virginia, USA). Supabase processes data as a data processor acting on our instructions and is subject to appropriate data processing agreements. For more information, see Supabase's Privacy Policy at supabase.com/privacy.

5b. Cloudflare, Inc. (Hosting and CDN)

Our website is served through Cloudflare's global content delivery network. Cloudflare processes certain technical data (including IP addresses and HTTP request data) as part of providing CDN, DDoS protection, and web application firewall services. Cloudflare acts as a data processor under our account agreement. See Cloudflare's Privacy Policy at cloudflare.com/privacypolicy.

5c. Regulatory and Law Enforcement Authorities

We may disclose personal and business data to US federal and international regulatory authorities when required by law. This includes, without limitation, disclosures to the Office of Foreign Assets Control ("OFAC"), the Financial Crimes Enforcement Network ("FinCEN"), the Internal Revenue Service ("IRS"), the US Department of Justice, or other competent authorities pursuant to lawful subpoenas, court orders, regulatory examination demands, or mandatory reporting obligations under the Bank Secrecy Act and OFAC sanctions programs. We are legally prohibited from notifying you if certain types of disclosures (such as SAR filings) are made.

5d. Professional Advisors

We may share information on a confidential basis with our legal counsel, external auditors, and accounting advisors as necessary for the provision of professional services, subject to applicable duties of confidentiality and privilege.

5e. Corporate Transactions

In the event of a merger, acquisition, asset sale, restructuring, or other corporate transaction involving Buhotec, personal data may be disclosed to prospective acquirers or transferred as part of the transaction, subject to appropriate confidentiality obligations. We will notify affected users via email or a prominent notice on our website if such a transaction results in a material change to how their data is used.

No Third-Party Marketing Sharing

We do not share personal information with any third-party marketers, data brokers, advertising networks, or analytics platforms. No personal data is used for interest-based advertising or cross-site tracking.

6. International Data Transfers

Buhotec is a US-based company and our primary database infrastructure is located in the United States (AWS us-east-1, Northern Virginia). If you are located outside the United States — including in the European Economic Area, the United Kingdom, Brazil, or other jurisdictions — your personal data will be transferred to and processed in the United States.

Transfers from the EEA and UK

For transfers of personal data from the EEA or UK to the United States, we rely on the European Commission's Standard Contractual Clauses ("SCCs") as the legal transfer mechanism under Art. 46 GDPR, incorporating the UK International Data Transfer Addendum where applicable. Our data processing agreements with Supabase and Cloudflare include appropriate SCC provisions.

Transfers from Brazil (LGPD)

For transfers of personal data from Brazil subject to the Lei Geral de Proteção de Dados ("LGPD"), we implement adequate safeguards as required by the Brazilian National Data Protection Authority (ANPD), including contractual clauses providing an equivalent level of protection to that afforded under the LGPD.

Transfers from Other Jurisdictions

For customers in other Latin American countries and jurisdictions, we implement appropriate contractual or organizational safeguards consistent with applicable local law. The primary security and organizational safeguards applicable to all transfers are described in Section 8 of this Policy.

7. Data Retention

We retain personal and business data for the periods specified below, which are determined by our operational needs and legal obligations:

Account and Business Registration Data

Retained for the duration of the active wholesale account relationship, plus seven (7) years after the account is closed or the relationship ends. This retention period supports our obligations under the Bank Secrecy Act, applicable IRS recordkeeping rules, and general commercial dispute resolution needs.

KYC and AML Compliance Records

Retained for a minimum of five (5) years from the date of the last transaction with the relevant customer, as required by 31 CFR § 1010.430 (BSA recordkeeping requirements) and FinCEN's Customer Due Diligence Rule (31 CFR § 1010.230). OFAC screening records are retained for a minimum of five (5) years from the date of each screening, consistent with OFAC guidance.

Transaction Records and Invoices

Retained for seven (7) years from the date of the transaction, consistent with IRS recordkeeping guidance under 26 U.S.C. § 6001 and general commercial statute of limitations requirements.

Website Technical Logs

Raw access logs and session data collected through Cloudflare are retained for ninety (90) days, after which they are automatically purged. Aggregated, de-identified analytics data may be retained longer for platform improvement purposes.

Account Correspondence

Business communications and correspondence related to a specific account or transaction are retained in accordance with the applicable account or transaction retention period described above.

After the applicable retention period expires, personal data is securely deleted or anonymized in accordance with our data disposal procedures, unless further retention is required by applicable law or necessary for the establishment, exercise, or defense of legal claims.

8. Security

We implement technical and organizational security measures designed to protect your personal and business data against unauthorized access, disclosure, alteration, and destruction. Our current security measures include the following:

Encryption at Rest

All data stored in our Supabase (PostgreSQL) database is encrypted at rest using AES-256 encryption, consistent with AWS and Supabase's default encryption standards for data at rest on EBS volumes and S3 storage.

Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.3 (with fallback to TLS 1.2 where required for compatibility). Unencrypted HTTP connections are automatically redirected to HTTPS. Cloudflare enforces strict HTTPS policies at the network edge.

Access Controls

Access to systems containing personal data is restricted on a need-to-know basis using role-based access controls ("RBAC"). Database credentials are never exposed client-side; all database interactions are mediated through authenticated server-side functions and Supabase Row Level Security ("RLS") policies.

Authentication

Wholesale buyer accounts are protected by strong password requirements and authentication mechanisms. Internal administrative access requires multi-factor authentication ("MFA").

Security Audits and Monitoring

We conduct periodic reviews of our security configurations, access logs, and data handling procedures. Cloudflare's Web Application Firewall (WAF) and DDoS mitigation tools provide continuous protection at the network layer.

Incident Response

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (where required under GDPR Art. 33) and will notify affected individuals where required under applicable law.

Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, and we encourage you to use strong, unique passwords and to contact us immediately if you suspect unauthorized access to your account.

9. Your Rights

Depending on your location and the applicable law, you may have the following rights with respect to your personal data. To exercise any of these rights, please contact us at [email protected]. We will respond to verified requests within the timeframes required by applicable law (generally 30 days, with an extension of up to 60 additional days where reasonably necessary).

Rights Under GDPR (EEA and UK)

  • Right of Access (Art. 15): You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data and information about how it is processed.
  • Right to Rectification (Art. 16): You have the right to request correction of inaccurate personal data or completion of incomplete data without undue delay.
  • Right to Erasure (Art. 17): You have the right to request deletion of your personal data in certain circumstances. Important exception: We cannot delete KYC, AML, OFAC, or transaction records that we are legally required to retain under the Bank Secrecy Act, FinCEN regulations, OFAC requirements, or other applicable law. Mandatory retention obligations take precedence over erasure requests.
  • Right to Restriction of Processing (Art. 18): You have the right to request that we restrict processing of your personal data in certain circumstances, for example while accuracy is being contested or an objection is pending.
  • Right to Data Portability (Art. 20): You have the right to receive a copy of personal data you have provided to us in a structured, commonly used, machine-readable format, and to transmit that data to another controller, where technically feasible and where processing is based on consent or a contract.
  • Right to Object (Art. 21): You have the right to object to processing based on legitimate interests. We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local supervisory authority. In the EU, this is the data protection authority ("DPA") of your member state. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk.

Rights Under CCPA (California)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with the following rights:

  • Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third parties with whom we share it.
  • Right to Delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions including our legal retention obligations described in Section 7.
  • Right to Opt Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising. This right is therefore inapplicable to our operations.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
  • Authorized Agent: You may designate an authorized agent to make a CCPA request on your behalf by providing written authorization or a power of attorney. We may require verification of your identity and the agent's authority.

To submit a CCPA request, please contact us at [email protected] with the subject line "CCPA Privacy Request."

Rights Under LGPD (Brazil)

If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD — Lei No. 13.709/2018) provides you with the following rights:

  • Confirmation of the existence of processing and access to your personal data
  • Correction of incomplete, inaccurate, or outdated data
  • Anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in non-compliance with the LGPD
  • Portability to another service or product provider
  • Deletion of personal data processed with your consent
  • Information about third parties with whom your data has been shared
  • Information about the possibility of withholding consent and the consequences of doing so
  • Revocation of consent

Brazilian users may exercise these rights by contacting us at [email protected]. The same exception regarding mandatory regulatory retention periods applies under the LGPD.

10. Cookies and Similar Technologies

Our website uses a limited set of cookies and similar technologies. We do not use cookies for advertising, remarketing, or cross-site behavioral tracking.

Essential Session Cookies

We use cookies that are strictly necessary for the operation of our Platform, including session management cookies that maintain your authenticated state while you are logged into your wholesale account. These cookies expire at the end of your browser session or within a short fixed period and cannot be disabled without impairing platform functionality.

Cloudflare Performance and Security Cookies

Cloudflare sets cookies (including the __cflb, __cf_bm, and cf_clearance cookies) to enable load balancing, bot mitigation, and security challenge functionality. These cookies are operationally necessary and are set automatically by Cloudflare's network infrastructure when you access our website. For details, see Cloudflare's cookie documentation.

No Third-Party Analytics or Advertising Cookies

We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, or any other third-party analytics or advertising platform that sets cookies or tracking pixels on our website. We do not engage in cross-site user tracking or interest-based advertising.

Managing Cookies

You can control cookie settings through your browser's privacy settings. Blocking all cookies may impair the functionality of authenticated areas of our Platform. Instructions for managing cookies in major browsers are available from your browser provider's help documentation.

11. Children's Privacy

Our Platform and services are designed exclusively for businesses and are not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. Account registration requires you to represent that you are an authorized representative of a registered legal entity and are of legal age to enter into contracts in your jurisdiction.

If we become aware that we have inadvertently collected personal information from a minor, we will take prompt steps to delete that information from our systems. If you believe that a minor has submitted personal information to us, please contact us immediately at [email protected].

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal obligations, or business operations. We will indicate the effective date of the current version at the top of this page.

For material changes — meaning changes that significantly affect how we use or share your personal data, or that affect your legal rights — we will provide at least 30 days' advance notice by:

  • Sending an email notification to the primary contact email address on file for your wholesale account; and/or
  • Posting a prominent notice on buhotec.com.

For non-material changes (such as clarifications, corrections of typographical errors, or updates to processor contact details), we will update this Policy without advance notice, and the updated version will take effect upon posting.

Your continued use of our Platform or services after the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms, to the extent permitted by applicable law. If you do not agree with a material change, you may request closure of your account by contacting us at [email protected] before the change takes effect.

13. Contact and Data Controller

Buhotec International LLC is the data controller responsible for personal data processed in connection with our wholesale platform and services.

Data Controller

Buhotec International LLC

10900 NW 21st St, Unit 110
Doral, Florida 33172
United States

Privacy Contact

For all privacy inquiries, data subject requests, GDPR/DPA correspondence, CCPA requests, and LGPD requests:

[email protected]

When contacting us regarding a privacy matter, please include your full name, company name, country of residence, and a description of your request. This will help us respond to you efficiently. For GDPR requests, please include "GDPR Data Request" in the subject line. For CCPA requests, include "CCPA Privacy Request." For LGPD requests, include "LGPD Data Request."

We will respond to all legitimate privacy requests within 30 days of receipt. In some cases — particularly for complex requests or those involving verification of identity — we may require up to 60 additional days, in which case we will notify you of the extension and the reason within the initial 30-day period.

For GDPR Data Protection Authority (DPA) correspondence: If you are in the EEA or UK and wish to lodge a formal complaint with a supervisory authority, you may contact the data protection authority in your country of residence. EU DPA contact information is available at edpb.europa.eu. UK residents may contact the ICO at ico.org.uk.

This Privacy Policy is effective as of January 1, 2026. It supersedes all prior versions. Last reviewed: May 2026.