Privacy notice
This notice explains which personal data we process in typical B2B workflows (inquiry, quote, order, delivery, RMA) and when you visit our website, and for which purposes.
Information on the processing of personal data (B2B)
This notice explains which personal data we process in typical B2B workflows (inquiry, quote, order, delivery, RMA) and when you visit our website, and for which purposes.
Controller
Tokama is a brand of Sixpol Electronics OHG. The controller under the GDPR is the entity named in the imprint.
- Sixpol Electronics OHG
- Bindergasse 9
- I-39100 Bozen
- Italy - South Tyrol
- Email (info@tokama.it)
- (+39) 0471 301082
- IT01726110214 / 01726110214
- KRRH6B9
- Lukas Stuffer
Data protection officer
If no statutory obligation applies, no DPO is appointed. Please use the contact address for privacy requests.
Which data do we process?
- Master & contact data (name, email, phone, company, role)
- Communication data (inquiries, emails, notes, quotes, attachments)
- Order & delivery data (items, quantity, destination, Incoterms, tracking, goods-in)
- Billing & payment data (billing address, VAT ID, payment status)
- RMA/service data (serial numbers, issue description, photos/videos optional, case steps)
- Website/technical data (IP address, logfiles, device/browser, timestamp/URL)
Purposes
- Handle inquiries, prepare quotes, pre-contractual steps
- Order handling, delivery/logistics, status communication
- Service and RMA handling incl. documentation
- Compliance with legal obligations (e.g. commercial/tax law)
- IT security, misuse/error analysis, website operation and improvement
- B2B relationship management within ongoing processes
Legal bases (selection)
- Art. 6(1)(b) GDPR – contract / pre-contract (inquiry, quote, order)
- Art. 6(1)(c) GDPR – legal obligation (e.g. retention duties)
- Art. 6(1)(f) GDPR – legitimate interests (IT operation/security, abuse prevention, B2B communications within processes)
- Art. 6(1)(a) GDPR – consent (e.g. optional cookies/tracking, if used)
Typical processing activities (overview)
| Activity | Data (examples) | Purpose | Legal basis | Retention (typical) |
|---|---|---|---|---|
| Inquiry / quote | Name, company, email, requirement, attachments | Reply, prepare a quote | Art. 6(1)(b) GDPR | Until case closed + internal periods |
| Order & delivery | Items, quantity, destination, Incoterms, tracking | Fulfilment, logistics, documentation | Art. 6(1)(b), where applicable (c) | Commercial/tax retention periods |
| Billing / accounting | Invoice data, VAT ID, payment status | Billing, evidence | Art. 6(1)(c) GDPR | Commercial/tax retention periods |
| RMA / service | Serial no., issue, photos/videos optional | Review, approval, handling, status | Art. 6(1)(b), where applicable (f) | Until case closed + internal periods |
| Website operation | IP, logfiles, browser/device, URL/time | Security, stability, troubleshooting | Art. 6(1)(f) GDPR | Short-term (log rotation) |
Recipients / processors
We use service providers (e.g. hosting, email, IT operations, logistics/transport, possibly ERP/CRM). They process data only on our instructions and to the required extent. Internal access is limited to necessary roles.
Transfers outside the EEA
If providers/sub-processors outside the EEA are used, transfers take place only with appropriate safeguards (e.g. Standard Contractual Clauses) and only as necessary.
Retention
We store data as long as necessary for the respective purposes. Business records are retained according to statutory retention periods. Communication and case data are generally kept until the case is closed and then according to internal deletion concepts and legal obligations.
Your rights
Depending on applicability, you have in particular the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR) – if consent is used
- Complaint to a supervisory authority
Cookies & similar technologies
We use technically necessary mechanisms to provide the website. Optional cookies/tracking are only used if enabled in the cookie settings (if available).
External content / services
External content (e.g. maps) is loaded only if enabled in cookie settings. Otherwise it remains disabled.
Security measures
We apply technical and organisational measures to protect data against loss, misuse and unauthorised access (e.g. access controls, updates, backups/monitoring as needed).
Automated decision-making
We do not use automated decision-making including profiling within the meaning of Art. 22 GDPR.
Changes to this notice
We update this notice when necessary (e.g. process or technology changes). The last update date is shown above.