Privacy Policy — TG Cerber
Last updated: 29 September 2026
This Privacy Policy explains how Oqtacore Sàrl (on behalf of the Partnership of XFounders Production Pte. Ltd. and Oqtacore SARL), ( "TGCerber", "we", "us", "our"), processes personal data in connection with the website tgcerber.com and the TG Cerber / Cerber service (the "Service"). It should be read together with our Terms of Use.
1. Who is responsible (operator and processor)
In this Policy, "operator" means the party that determines why and how personal data is processed (the "controller" under the EU GDPR); "processor" means a party that processes data on the operator's behalf and instructions.
- For personal data about website visitors and account holders (e.g. contact, billing, and support data), TGCerber acts as the operator.
- For content you connect and archive through the Service (Telegram messages, files, and account/session metadata of the accounts you connect), TGCerber acts as a processor on behalf of the customer organization, which is the operator of that content. The customer decides what is archived and who has access, and is responsible for the lawful basis for the processing (see the Terms, Section 8). For on-premises deployments, that content stays in the customer's infrastructure and we do not access it.
2. What data we process
2.1. Website and account data (as operator):
- identification and contact data (name, company, email, phone);
- account and authentication data;
- billing and transaction data (handled by payment providers; we do not store full card numbers);
- support communications;
- technical and usage data (IP address, device and browser data, logs) and cookies.
2.2. Service content (as processor, on the customer's behalf):
- messages and files from the Telegram accounts the customer connects and selects for archiving;
- session, device, and login metadata of connected accounts.
3. Purposes and legal bases
We process data for which we are the operator to: provide and secure the Service and website; manage accounts, billing, and support; comply with legal obligations; and improve and protect the Service. Depending on your location, our legal bases include performance of a contract, our legitimate interests, consent (for example, certain cookies), and compliance with law. Content for which we act as processor is processed only on the customer's documented instructions.
4. Cookies and analytics
The website may use necessary cookies and, with consent where required, analytics cookies. You can manage cookies in your browser and, where offered, through a consent banner.
5. Sharing and sub-processors
We share personal data only as needed: with service providers acting on our behalf (for example, hosting, infrastructure, payment, and support tools) under appropriate confidentiality and data-protection terms; when required by law or to protect rights and safety; and in a merger, acquisition, or sale of assets. We do not sell personal data.
6. International transfers
We are based in Switzerland. Where personal data is transferred outside Switzerland or the EEA, we rely on an adequacy decision or appropriate safeguards (such as standard contractual clauses).
7. Retention
We keep personal data only as long as necessary for the purposes above or as required by law. For archived Service content, retention follows the customer's settings and the Terms (Section 8.5): after a paid archive plan ends, data remains available to view and export for a limited period, then is stored encrypted without access until scheduled deletion; exact dates are shown in the account.
8. Security
We apply reasonable technical and organizational measures, including encryption of the archive (with the customer's key in the cloud option; keys and data remaining within the customer's perimeter for on-premises deployments). A lost encryption key cannot be recovered by us. No method of protection is absolute, and we cannot guarantee absolute security.
9. Your rights
Depending on applicable law (including the Swiss Federal Act on Data Protection and, where relevant, the EU GDPR), you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. You may also lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC). To exercise your rights regarding data for which we are the operator, contact us at info@oqtacore.com.
United States. There is no single US federal privacy law; instead, state consumer-privacy laws may apply. If you are a resident of a US state with such a law — for example, the California Consumer Privacy Act (CCPA), as amended by the CPRA, and comparable laws in states such as Virginia, Colorado, Connecticut, and Utah — you may have the right to know about, access, correct, delete, and obtain a copy of your personal data, and to opt out of the "sale" or "sharing" of personal data and of certain targeted advertising. We do not sell your personal data, and we will not discriminate against you for exercising these rights. Sector-specific US laws (for example, on health or financial data) may also apply where relevant.
Requests about archived Service content: because the customer organization is the operator of the content it connects and archives, please direct such requests to that organization; we will assist it as its processor.
10. Children
The Service is intended for business use and is not directed to children under 16.
11. Changes
We may update this Policy. Material changes will be notified by reasonable means (for example, on the website or by email). Continued use after changes take effect means you accept the updated Policy.
12. Contact
Oqtacore Sàrl
Route de Divonne 44, 1260 Nyon, Switzerland
Email: info@oqtacore.com
Support: @TGCerbersupportbot (Telegram)