Privacy

Privacy notice

This notice explains which personal data we process in typical B2B workflows (inquiry, quote, order, delivery, RMA) and when you visit our website, and for which purposes.

Last updated: 29.03.2026 Tokama Order-based sourcing in Europe

Information on the processing of personal data (B2B)

This notice explains which personal data we process in typical B2B workflows (inquiry, quote, order, delivery, RMA) and when you visit our website, and for which purposes.

Controller

Tokama is a brand of Sixpol Electronics OHG. The controller under the GDPR is the entity named in the imprint.

  • Sixpol Electronics OHG
  • Bindergasse 9
  • I-39100 Bozen
  • Italy - South Tyrol
  • Email (info@tokama.it)
  • (+39) 0471 301082
  • IT01726110214 / 01726110214
  • KRRH6B9
  • Lukas Stuffer
Data protection officer

If no statutory obligation applies, no DPO is appointed. Please use the contact address for privacy requests.

Which data do we process?
  • Master & contact data (name, email, phone, company, role)
  • Communication data (inquiries, emails, notes, quotes, attachments)
  • Order & delivery data (items, quantity, destination, Incoterms, tracking, goods-in)
  • Billing & payment data (billing address, VAT ID, payment status)
  • RMA/service data (serial numbers, issue description, photos/videos optional, case steps)
  • Website/technical data (IP address, logfiles, device/browser, timestamp/URL)
Purposes
  • Handle inquiries, prepare quotes, pre-contractual steps
  • Order handling, delivery/logistics, status communication
  • Service and RMA handling incl. documentation
  • Compliance with legal obligations (e.g. commercial/tax law)
  • IT security, misuse/error analysis, website operation and improvement
  • B2B relationship management within ongoing processes
Legal bases (selection)
  • Art. 6(1)(b) GDPR – contract / pre-contract (inquiry, quote, order)
  • Art. 6(1)(c) GDPR – legal obligation (e.g. retention duties)
  • Art. 6(1)(f) GDPR – legitimate interests (IT operation/security, abuse prevention, B2B communications within processes)
  • Art. 6(1)(a) GDPR – consent (e.g. optional cookies/tracking, if used)
Typical processing activities (overview)
Activity Data (examples) Purpose Legal basis Retention (typical)
Inquiry / quote Name, company, email, requirement, attachments Reply, prepare a quote Art. 6(1)(b) GDPR Until case closed + internal periods
Order & delivery Items, quantity, destination, Incoterms, tracking Fulfilment, logistics, documentation Art. 6(1)(b), where applicable (c) Commercial/tax retention periods
Billing / accounting Invoice data, VAT ID, payment status Billing, evidence Art. 6(1)(c) GDPR Commercial/tax retention periods
RMA / service Serial no., issue, photos/videos optional Review, approval, handling, status Art. 6(1)(b), where applicable (f) Until case closed + internal periods
Website operation IP, logfiles, browser/device, URL/time Security, stability, troubleshooting Art. 6(1)(f) GDPR Short-term (log rotation)
Recipients / processors

We use service providers (e.g. hosting, email, IT operations, logistics/transport, possibly ERP/CRM). They process data only on our instructions and to the required extent. Internal access is limited to necessary roles.

Transfers outside the EEA

If providers/sub-processors outside the EEA are used, transfers take place only with appropriate safeguards (e.g. Standard Contractual Clauses) and only as necessary.

Retention

We store data as long as necessary for the respective purposes. Business records are retained according to statutory retention periods. Communication and case data are generally kept until the case is closed and then according to internal deletion concepts and legal obligations.

Your rights

Depending on applicability, you have in particular the following rights:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Withdrawal of consent (Art. 7(3) GDPR) – if consent is used
  • Complaint to a supervisory authority
Cookies & similar technologies

We use technically necessary mechanisms to provide the website. Optional cookies/tracking are only used if enabled in the cookie settings (if available).

External content / services

External content (e.g. maps) is loaded only if enabled in cookie settings. Otherwise it remains disabled.

Security measures

We apply technical and organisational measures to protect data against loss, misuse and unauthorised access (e.g. access controls, updates, backups/monitoring as needed).

Automated decision-making

We do not use automated decision-making including profiling within the meaning of Art. 22 GDPR.

Changes to this notice

We update this notice when necessary (e.g. process or technology changes). The last update date is shown above.

Back to home
Quick to contact Contact