Privacy Policy

Privacy policy

Guidelines on data protection and corporate confidentiality

Revision: August 2026

This document sets out the guidelines adopted by TonerDeck (hereinafter "the Company" or "the Operator"), whose registered office is located in Estonia, concerning the collection, processing and protection of information relating to its customers and commercial partners (hereinafter "the Buyer" or "the B2B Partner") who interact with our e-commerce infrastructure.

As a participant in the European market, we operate in accordance with the mandatory provisions of the General Data Protection Regulation (GDPR).

1. Categories of data collected

In order to fulfil our contractual obligations, the collection of information is essential to processing orders and to issuing B2B invoices correctly. The Operator collects:

  • The company name and tax identifiers (for example, the intra-Community VAT number).
  • The identity of legal representatives or of those responsible for purchasing.
  • Operational contact details (delivery and billing addresses, business email addresses and telephone numbers).
  • Commercial history and supply profiles.

2. Purposes of processing

The data collected is used exclusively for the following purposes:

  • Order processing, logistics tracking and application of the tax regime (VAT reverse charge).
  • Improving the performance and the range of our catalogue.
  • Sending strategic communications — in particular new B2B campaigns, price changes and stock news — to the email address provided.
  • Adapting use of the website to the client company's profile.

3. Security protocols

Protecting your information is a non-negotiable commitment for TonerDeck.

In order to reduce the risk of intrusion, misappropriation or data leakage, the Company puts in place a set of physical protection measures and electronic firewalls. Commercial and payment data is isolated on highly secure servers and handled in the strictest confidence.

4. Management of trackers (cookies)

In order to assess how smoothly the platform runs and to monitor traffic indicators, we use diagnostic files (cookies) that are installed on the user's device. This analysis helps us adjust the store's architecture and offer an optimised experience suited to the speed requirements of the B2B sector.

5. Restrictions on sharing with third parties

True to its commercial integrity, the Operator does not monetise, license or transfer its database to third parties.

The sharing of information is strictly limited to logistics partners and concerns only the data necessary for the proper physical delivery of goods.

Any exception to this rule may occur only by judicial decision.

6. Rights of the commercial partner (GDPR)

The European framework gives you control over your data. You may request at any time access to your data, its rectification, its erasure (the right to be forgotten) or its portability.

To exercise these rights, or to object to the processing of data for statistical purposes, simply contact our compliance department electronically.

7. Competent jurisdiction

All operations for the retention and processing of documents are governed by the legislation of the Republic of Estonia. In the event of a dispute concerning the data protection policy, the parties acknowledge the exclusive jurisdiction of the Estonian courts for its resolution.

Data controller

Your data is collected and processed by TonerDeck, whose registered office is at Sepapaja tn 12-850, Lasnamäe linnaosa, Tallinn, 11415 Harju maakond, Estonia. This company is responsible for processing your personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.