Scope, operator, and privacy roles
This Privacy Policy takes effect on 31 August 2026 and explains how CX24 Digital Technologies Pvt. Ltd. (“CX24,” “we,” “us,” or “our”) handles personal data through Ignorre. Ignorre is a product and service brand operated by CX24.
- This Policy covers Ignorre websites, accounts, applications, domain and registrar services, infrastructure, email, analytics, support, managed projects, billing, and enabled integrations.
- CX24 is responsible for personal data used to operate accounts, administer the customer relationship, provide registrar services, secure the platform, bill customers, meet legal duties, and communicate about Ignorre.
- For content a Customer places in hosted email, websites, analytics, infrastructure, projects, or other Customer-controlled workspaces, the Customer normally decides why and how that content is processed. CX24 then acts on the Customer’s documented instructions, subject to the service agreement and law.
- A service-specific privacy notice, data-processing agreement, registry notice, or Order may add details for a particular service. It controls for that subject if it expressly differs from this general Policy.
- This Policy does not govern an independent third party’s website or service merely because Ignorre links to or integrates with it. That party’s own privacy notice applies to its independent processing.
Personal data we collect
The data collected depends on the Services used, the role of the person, the actions requested, the providers enabled, and legal or registry requirements.
- Account and identity data: name, email address, organization, role, team membership, contact details, profile settings, authentication factors, verification results, recovery details, and account preferences.
- Commercial data: enquiries, quotes, Orders, plans, subscriptions, invoices, account credits, payment-method metadata, transaction and refund status, renewal settings, usage, and support history.
- Domain and registrar data: domain names, registrant and administrative or technical contact data, nameservers, DNSSEC material, transfer and authorization information, locks, verification evidence, renewal choices, registry responses, abuse reports, and compliance records.
- Infrastructure and operations data: hosting accounts, virtual resources, IP addresses, DNS zones and records, mail domains, mailboxes, aliases, policies, website projects, provider bindings, resource measurements, operation results, configuration and change history.
- Customer content: email and attachments, contacts, calendars, project briefs, messages, uploaded files, website source, analytics events, support attachments, assistant prompts, selected knowledge, and generated output.
- Technical, device, and security data: IP address, browser and device details, language, screen information, request and response metadata, timestamps, sessions, cookies or local-storage identifiers, audit events, error reports, rate-limit events, fraud signals, and security findings.
- Communications and feedback: support requests, privacy or abuse reports, survey responses, call or meeting notes where provided, and messages exchanged with CX24 personnel or through a managed project.
Where personal data comes from
We collect data directly, automatically through use of Ignorre, and from parties involved in a requested Service.
- Directly from you when you register, configure an account, place an Order, submit content, contact support, complete verification, or operate a Service.
- From the Customer organization, its account owner, administrator, employee, reseller, agent, collaborator, sender, recipient, or other person authorized to provide the data.
- From registries, registry service providers, registrars, escrow or verification providers, hosting and infrastructure providers, DNS and mail systems, payment and identity providers, and other enabled integrations.
- From technical operation of the website and Services, including logs, security tools, cookies, local storage, measurements, and first-party analytics.
- From public or authoritative sources used for a requested operation, such as RDAP, WHOIS, DNS, certificate transparency, public websites, search engines, and government or sanctions lists where lawfully relevant.
Why we use personal data
CX24 uses personal data only for identified service, security, relationship, improvement, and legal purposes.
- Create and authenticate accounts, maintain sessions, recover access, apply roles and permissions, and prevent unauthorized access.
- Review and fulfil Orders and operate domain, registry, hosting, VPS, DNS, certificate, email, website, analytics, SEO, managed-project, billing, support, and provider-connected workflows.
- Verify identity, authority, registrant contacts, service eligibility, and payment or provider instructions where required.
- Generate invoices, reconcile payments, administer credits and refunds, prevent duplicate operations, maintain financial and audit records, and satisfy applicable accounting and tax obligations.
- Monitor performance and service health, investigate errors, abuse and fraud, enforce terms, respond to incidents, preserve evidence, and protect customers, providers, rights, and infrastructure.
- Respond to support, privacy, security, billing, domain, and service requests and send transaction, security, renewal, operational, and policy communications.
- Measure and improve usability, accessibility, reliability, capacity, and feature adoption using proportionate analytics, testing, aggregated information, and operational metrics.
- Provide an AI-assisted, publishing, measurement, or other optional provider feature only when a Customer invokes that enabled capability.
Legal grounds and fair processing
The legal ground depends on the purpose, relationship, and law that applies. We do not rely on consent where processing is necessary for another valid ground unless law requires consent.
- To perform a contract or take requested steps before a contract, including account, Order, domain, infrastructure, email, project, billing, and support operations.
- To comply with legal obligations and permitted uses under applicable Indian law, including the Digital Personal Data Protection Act, 2023 as and when its relevant provisions apply, and applicable registry, ICANN, accounting, tax, dispute, security, and law-enforcement requirements.
- For legitimate interests recognized by applicable law, such as securing and administering Ignorre, preventing fraud and abuse, maintaining records, improving Services, supporting Customers, and protecting legal rights, after considering the interests and rights of affected people.
- With consent where required, including for a specific optional use, non-essential browser storage, or marketing. Consent may be withdrawn through the available setting or contact method without affecting processing already lawfully completed.
- To establish, exercise, or defend legal claims; protect vital interests; respond to emergencies; or perform another ground permitted by the law that applies.
Domain registration, RDAP, and registry data
Domain services require personal and operational data to move through the domain-name ecosystem. The exact recipients and public-access rules depend on the TLD, registrar-of-record, registry, location, and applicable policy.
- Registration, transfer, renewal, contact, verification, DNSSEC, dispute, abuse, and lifecycle operations may require data to be sent to a registry, registry service provider, another registrar, data-escrow provider, verification service, rights-protection or dispute provider, privacy or proxy provider, or competent authority.
- Some registration data may be published or made available through RDAP, WHOIS, gated disclosure, or another registration-data service where policy and law require or permit it. Redaction or privacy services may limit public display but do not eliminate underlying collection or authorized disclosure.
- Registrant data must be accurate and current. Verification or investigation may require additional identity, authority, contact, transaction, or dispute evidence.
- Registry, ICANN, escrow, dispute, abuse, audit, security, and legal requirements can require retention after a registration is transferred, expires, or is cancelled.
- A domain reseller or delegated administrator may collect data before sending it to CX24. That party is independently responsible for its notices, permissions, security, and lawful handling unless a written agreement states otherwise.
Payments, billing, and fraud prevention
CX24 processes the commercial and transaction information needed to quote, invoice, collect, reconcile, refund, account for, and audit Services and to detect unauthorized or fraudulent activity.
- The data used depends on the payment method and can include payer identity, billing contact, amount, currency, invoice reference, transaction identifier, payment status, limited payment-method metadata, reconciliation evidence, and risk signals.
- Where a payment provider is enabled, that provider processes payment credentials under its own terms and privacy notice. Ignorre receives the information the provider returns to confirm, reconcile, dispute, or refund the transaction.
- Bank-transfer evidence may be reviewed to match funds to the correct Customer and invoice. Do not upload unrelated bank, identity, or account information.
- Financial, invoice, tax, transaction, chargeback, and fraud-prevention records may be retained for the period required by law, payment-network rules, dispute needs, and legitimate recordkeeping.
Customer content and communications
Hosted email, webmail, contacts, calendars, project materials, support files, website source, analytics events, and assistant conversations can contain personal, confidential, or sensitive data selected by the Customer.
- Customers determine what content is submitted, the people who may access it, the purpose and lawful ground, retention and deletion settings, recipients, and any notices or permissions required from users, contacts, employees, clients, or visitors.
- CX24 accesses Customer content only as needed to provide and secure the Service, follow authorized instructions, investigate a reported problem, prevent abuse, comply with an Order, or meet legal obligations.
- Authorized Customer administrators may be able to access, export, route, retain, or delete content and view user activity. Users should direct organization-controlled content requests to the relevant Customer administrator.
- Avoid submitting data that is not needed. Configure roles, mail forwarding, automation, sharing, analytics capture, project access, integrations, and retention in a way appropriate to the sensitivity and intended use.
AI-assisted processing and automated output
When a Customer deliberately invokes an enabled AI capability, selected prompts, source material, content, settings, and contextual data may be sent to the configured provider to produce the requested result.
- A disabled or activation-required AI capability does not send content to an AI provider. The available interface or service documentation identifies when an external provider connection is required.
- Customers must decide whether input is authorized, necessary, and suitable for the configured provider, especially where it contains personal, confidential, regulated, proprietary, or third-party data.
- Provider retention, access, model-improvement use, and processing location depend on the active provider configuration and contract. Relevant service-specific information is supplied through the integration, Order, or documentation.
- AI output may contain personal data or inferences and can be inaccurate. Customers must review output and avoid using it for a legally significant decision about a person without appropriate authority, safeguards, transparency, and human review.
International processing and transfers
The Internet, domain registries, and enabled providers can process personal data outside the country where a person is located. Locations vary by TLD, resource, provider, and Customer configuration.
- CX24 considers contractual, technical, and organizational safeguards, the nature of the data, provider role, and applicable transfer restrictions when selecting and operating a provider.
- Where law requires a transfer mechanism, CX24 uses an available lawful mechanism, such as an adequacy decision, approved contractual protection, consent where appropriate, or another permitted basis.
- Transfers from India are handled subject to restrictions and requirements under applicable Indian data-protection law as and when those requirements apply.
- Service-specific provider and data-location information is supplied through the applicable Order, integration, or documentation where it is material or legally required.
Retention, account closure, and deletion
Personal data is retained only as long as reasonably necessary for the purpose collected, the active Service, security and continuity, dispute resolution, enforcement, and legal, accounting, tax, registry, escrow, or audit requirements.
- Account, domain, invoice, transaction, consent, complaint, and audit records may remain after account closure where required for registry policy, legal compliance, fraud prevention, security, financial recordkeeping, or the establishment or defence of claims.
- Customer content is kept while the relevant Service is active and then returned, exported, or deleted according to the Order, authorized instruction, provider lifecycle, technical backup cycle, and law.
- Security logs and session records are retained according to operational risk and investigation needs. Revoked credentials may leave hashes or audit metadata needed to prevent reuse and preserve an accountable history.
- Backups rotate on a limited operational cycle. Deletion from active systems may not remove every backup copy immediately; retained copies remain protected and are not restored into ordinary use except for continuity, security, or recovery.
- Where no fixed period is prescribed, retention is decided using the amount, nature, and sensitivity of the data, service lifecycle, purpose, risk of harm, Customer instruction, and applicable legal requirements.
- Data may be anonymized so that it no longer identifies a person. Properly anonymized information may be retained and used for security, reliability, capacity, statistical, and improvement purposes.
Security and incident handling
CX24 uses administrative, technical, and organizational measures designed for the nature of Ignorre, the processing, and the risks involved. No Internet service can guarantee absolute security.
- Measures can include password hashing, session expiry and revocation, multi-factor authentication where available, role-based authorization, protected provider credentials, tenant boundaries, audit logging, rate limits, input validation, encrypted transport, monitoring, and fail-closed capability gates.
- Access is limited according to role and operational need. Personnel and service providers with authorized access are subject to applicable confidentiality and security obligations.
- Suspected incidents are assessed, contained, investigated, remediated, and documented proportionately. CX24 notifies affected Customers, individuals, providers, or authorities when and as required by applicable law or contract.
- Customers must protect credentials and endpoints, use appropriate roles and available security controls, maintain backups where needed, keep account details current, and promptly report suspected compromise to support@ignorre.net.
Your privacy rights and choices
Rights depend on the person’s location, CX24’s role, and applicable law. Subject to verification and legal exceptions, a person may be able to request information about processing, access, correction, completion, updating, deletion, restriction, objection, portability, or withdrawal of consent.
- Where the Digital Personal Data Protection Act, 2023 applies and its relevant provisions are in force, an eligible Data Principal may exercise applicable rights to access information about processing, correct, complete and update personal data, request erasure, seek grievance redressal, and nominate another individual as permitted by law.
- Consent can be withdrawn as easily as it was given through an available setting or by contacting us. Withdrawal does not affect earlier lawful processing and may prevent a requested optional Service from continuing.
- Marketing communications can be stopped through the unsubscribe method provided or by contacting us. Security, transaction, account, domain-lifecycle, and other essential service notices may still be sent.
- Where applicable, a person may complain to the Data Protection Board of India or another competent privacy or consumer authority after using the available grievance process, without losing any other remedy provided by law.
- CX24 does not discriminate unlawfully because a person exercises a privacy right. A request can be limited or refused where identity or authority cannot be verified, an exception applies, the request affects another person’s rights, or law permits the response.
How to submit a privacy request
Send a request or privacy grievance to support@ignorre.net and describe the account, relationship, right, and data involved without including unnecessary secrets or identity documents.
- CX24 may ask for proportionate information to verify identity, authority, and the correct account before disclosing, changing, exporting, or deleting data.
- An authorized agent may submit a request where permitted, but authority and the identity of the relevant person may need to be verified.
- If the data is controlled by a Customer organization, CX24 may refer the request to that Customer or help it respond as its processor. Contacting the Customer administrator first can be the fastest route for organization-controlled content.
- CX24 will acknowledge and respond within the period required by applicable law. Complex, numerous, or technically difficult requests may take longer where law permits and the requester will be informed when required.
- A request is normally free. A reasonable fee or refusal may apply only where permitted for manifestly unfounded, excessive, or repetitive requests.
Children’s data
Ignorre is a business platform intended for authorized adults and is not directed to children under 18.
- Do not create an account as a child or submit a child’s personal data unless the Customer has a lawful, necessary, and appropriately safeguarded reason and has met applicable parental-consent and child-protection duties.
- Where Indian law applies, the Customer and CX24 will follow applicable requirements for children’s data and verifiable consent as and when those requirements are in force.
- Contact support@ignorre.net if you believe a child’s personal data was submitted improperly. CX24 may verify the report and restrict or delete the data where appropriate and lawful.
Changes, privacy contact, and grievances
CX24 may update this Policy as Ignorre Services, providers, practices, and law change. Material changes receive a new version or effective date and reasonable notice through the website, account, email, or another appropriate channel.
- For privacy questions, rights requests, security concerns, or a privacy grievance, contact the CX24 privacy and grievance intake at support@ignorre.net.
- Include enough information to route and investigate the matter, but do not send passwords, recovery codes, full payment credentials, or unrelated identity documents.
- If an Order or legally required notice identifies an additional privacy representative, grievance contact, or formal-notice method, that information also applies.
Document updates
Material changes are versioned and communicated.
CX24 Digital Technologies Pvt. Ltd. may update this document as Ignorre services, providers, law, or commercial terms change. Material changes will receive a new version or effective date and reasonable notice through the website, account, email, or another appropriate channel. Where consent is required by law, an update will not take effect merely because the service continues to be used.

