Skip to main content
GDPR

The GDPR-compliant CAPTCHA

Protect your forms and logins from bots – without a consent banner, without cookies and without sending visitor data outside the EU.

  • No consent banner needed
  • EU-only processing
  • DPA on every plan

No cookies, no consent friction

The widget sets no cookies and stores nothing permanently in the browser – so it does not force a consent banner onto your visitors.

EU-only processing

All requests are processed and stored exclusively in EU data centers. No third-country transfers, no Schrems II headaches.

Processor with DPA on every plan

You remain the controller, CaptchaFox works strictly on your instructions under Art. 28 GDPR – with a DPA included on every plan.

GDPR compliance checklist

Point by point: how CaptchaFox meets the requirements your data protection officer will ask about.

  • Cookie-free verification

    Art. 5(3) ePrivacy DirectiveArt. 5(1)(c) GDPR

    No cookies, no localStorage, no persistent identifiers in the visitor's browser. Verification does not require consent under the ePrivacy rules implemented across the EU.

  • Data minimization by design

    Art. 5(1)(c) GDPRArt. 25 GDPR

    The widget processes the IP address together with other technical and usage signals needed to tell humans and bots apart – never more than verification requires.

  • Clear lawful basis

    Art. 6(1)(f) GDPR

    Bot protection is typically based on your legitimate interest in the security of your website – no separate consent flow needed.

  • Processor role with DPA

    Art. 28 GDPR

    CaptchaFox processes data exclusively on your behalf and according to your instructions. A Data Processing Agreement is available on every plan.

  • No third-country transfers

    Art. 44–49 GDPR

    Processing and storage happen exclusively in EU data centers, so the GDPR's restrictions on international transfers simply do not apply.

  • Transparency for your privacy policy

    Art. 12–14 GDPR

    We document exactly what the widget processes so you can fulfil your information duties towards visitors with a single paragraph.

  • Data subject rights supported

    Art. 15–22 GDPR

    We support you in answering access, erasure and objection requests and forward any requests addressed to us to you as the controller.

  • Technical and organizational measures

    Art. 32 GDPR

    Identifying data such as IP addresses is anonymized as early as possible, for example through hashing, and never stored permanently in plain text.

  • Storage limitation

    Art. 5(1)(e) GDPR

    Personal verification data is kept only as long as the bot decision requires. Beyond that, no signals remain that could re-identify or track individual visitors.

Why CaptchaFox works without a consent banner

Consent requirements are triggered by storing or reading information on a visitor's device – cookies, localStorage, fingerprinting identifiers. The CaptchaFox widget does none of that. It evaluates the signals a browser already sends, anonymizes identifying data right away and returns a verdict. That is why bot protection with CaptchaFox can rely on legitimate interest instead of consent, while cookie-based CAPTCHAs like Google reCAPTCHA drag a consent requirement into every form they protect.

Frequently asked questions

Everything you need to know. Can't find your answer? Contact our support team.

Is CaptchaFox GDPR compliant?
Yes. The widget works without cookies, processes only the data needed to distinguish humans from bots, keeps all processing in EU data centers and comes with a Data Processing Agreement pursuant to Art. 28 GDPR on every plan.
Do I need visitor consent to use CaptchaFox?
Typically no. Because the widget stores nothing on the visitor's device, the ePrivacy consent requirement is not triggered, and processing can be based on your legitimate interest in protecting your website (Art. 6(1)(f) GDPR).
Is reCAPTCHA GDPR compliant?
Google reCAPTCHA sets cookies and transfers visitor data to US servers – European data protection authorities have repeatedly objected, and courts have held that its cookies require prior consent. Since Google's 2026 shift to a processor model, website operators also carry the full GDPR responsibility for it themselves. CaptchaFox avoids these issues by design.
What data does the CaptchaFox widget process?
The IP address, plus other technical and usage signals needed to assess the request. Identifying data such as the IP address is anonymized as early as possible, for example through hashing, and is never used for advertising or profiling.
Does CaptchaFox transfer data outside the EU?
No. All data is processed and stored exclusively in EU data centers, and both of our subprocessors are European companies processing in the EU. The transfer rules of Art. 44–49 GDPR do not come into play.
What do I need to add to my privacy policy?
A short section naming CaptchaFox (Scoria Labs GmbH) as your processor for bot protection, the categories of data described above, legitimate interest as the legal basis and a link to the CaptchaFox end-user privacy policy for the full details.

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices