The GDPR-compliant CAPTCHA
Protect your forms and logins from bots – without a consent banner, without cookies and without sending visitor data outside the EU.
- No consent banner needed
- EU-only processing
- DPA on every plan
No cookies, no consent friction
The widget sets no cookies and stores nothing permanently in the browser – so it does not force a consent banner onto your visitors.
EU-only processing
All requests are processed and stored exclusively in EU data centers. No third-country transfers, no Schrems II headaches.
Processor with DPA on every plan
You remain the controller, CaptchaFox works strictly on your instructions under Art. 28 GDPR – with a DPA included on every plan.
GDPR compliance checklist
Point by point: how CaptchaFox meets the requirements your data protection officer will ask about.
Cookie-free verification
Art. 5(3) ePrivacy DirectiveArt. 5(1)(c) GDPRNo cookies, no localStorage, no persistent identifiers in the visitor's browser. Verification does not require consent under the ePrivacy rules implemented across the EU.
Data minimization by design
Art. 5(1)(c) GDPRArt. 25 GDPRThe widget processes the IP address together with other technical and usage signals needed to tell humans and bots apart – never more than verification requires.
Clear lawful basis
Art. 6(1)(f) GDPRBot protection is typically based on your legitimate interest in the security of your website – no separate consent flow needed.
Processor role with DPA
Art. 28 GDPRCaptchaFox processes data exclusively on your behalf and according to your instructions. A Data Processing Agreement is available on every plan.
No third-country transfers
Art. 44–49 GDPRProcessing and storage happen exclusively in EU data centers, so the GDPR's restrictions on international transfers simply do not apply.
Transparency for your privacy policy
Art. 12–14 GDPRWe document exactly what the widget processes so you can fulfil your information duties towards visitors with a single paragraph.
Data subject rights supported
Art. 15–22 GDPRWe support you in answering access, erasure and objection requests and forward any requests addressed to us to you as the controller.
Technical and organizational measures
Art. 32 GDPRIdentifying data such as IP addresses is anonymized as early as possible, for example through hashing, and never stored permanently in plain text.
Storage limitation
Art. 5(1)(e) GDPRPersonal verification data is kept only as long as the bot decision requires. Beyond that, no signals remain that could re-identify or track individual visitors.
Why CaptchaFox works without a consent banner
Consent requirements are triggered by storing or reading information on a visitor's device – cookies, localStorage, fingerprinting identifiers. The CaptchaFox widget does none of that. It evaluates the signals a browser already sends, anonymizes identifying data right away and returns a verdict. That is why bot protection with CaptchaFox can rely on legitimate interest instead of consent, while cookie-based CAPTCHAs like Google reCAPTCHA drag a consent requirement into every form they protect.
Frequently asked questions
Everything you need to know. Can't find your answer? Contact our support team.
Is CaptchaFox GDPR compliant?
Do I need visitor consent to use CaptchaFox?
Is reCAPTCHA GDPR compliant?
What data does the CaptchaFox widget process?
Does CaptchaFox transfer data outside the EU?
What do I need to add to my privacy policy?
More privacy regulations
Fight bots and protect your users' data.
Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.