MIT-licensed proof-of-work CAPTCHA from Brno (BAU Software s.r.o.) with a public DPA and EU-only Cloud endpoints, though the Cloud itself runs on AWS.
- FROM
- —
- CLOUD ACT
- MATERIAL
A single roll-up of ownership and CLOUD Act exposure.
Trustcaptcha GmbH, Hans-Böckler-Straße 32, 80995 Munich, Germany (HRB 287710, Munich Local Court)
Munich proof-of-work CAPTCHA (Trustcaptcha GmbH) on Hetzner Nuremberg, from 8 EUR/month, with audit logs but no published DPA or sub-processor list.
TrustCaptcha, in the CAPTCHA & bot protection category, is a European service with Germany as its hosting location and at most minor, transient US exposure under the CLOUD Act.
TrustCaptcha is a proof-of-work CAPTCHA from Trustcaptcha GmbH in Munich, now sold under the TrustComponent brand alongside a status page and a VAT checker. The jurisdiction and infrastructure are straightforward: German GmbH, and the service resolves to Hetzner in Nuremberg, so both the operator and the servers are in Germany. Every plan is advertised as including "GDPR, EU hosted & DPA". What we could not do is verify the paperwork, and that is what holds the score at 3/5: there is no public DPA URL and no named sub-processor list, only a privacy policy that describes recipients by role (hosting providers, error logging, accounting, analytics, payment processors, advertising networks). The named third parties that do appear are Stripe Payments Europe Ltd. (Ireland) for billing, plus a Google Ads conversion cookie and an OpenReplay session-replay cookie on the vendor's own marketing site: Minor. The proof-of-work design is worth noting on its own, because it shifts the work to the visitor's browser instead of profiling the visitor.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
Where ultimate control over the operating company sits.
TrustCaptcha is a CAPTCHA built on dynamic proof-of-work, operated by Trustcaptcha GmbH in Munich and sold under the wider TrustComponent brand, which also covers a status page product and a VAT-ID checker. Rather than asking a visitor to identify traffic lights or profiling their behaviour against a global signal graph, the widget makes the browser compute a small cryptographic puzzle whose difficulty adapts to the assessed risk. That design choice is the reason it can work without a behavioural profile of the visitor, and it pairs with honeypot verification, bot detection and risk scoring, IP allow and block lists, custom access rules and geoblocking, bypass keys, environments, team seats with roles, and audit logs on the higher tiers.
On jurisdiction it is a simple read: a German GmbH registered in Munich, with the service resolving to Hetzner infrastructure in Nuremberg, so operator and servers are both in Germany. Every plan is marketed as "GDPR, EU hosted & DPA", and there is a 99.9% uptime commitment from the entry tier upwards.
The gap is documentation. There is no publicly reachable DPA and no named sub-processor list: the privacy policy lists recipients by function (hosting providers, error logging, accounting service providers, IT service providers, analytics, data storage, payment processors, advertising networks) without naming any of them. The named third parties we could confirm are Stripe Payments Europe Ltd. in Ireland for payments, a Google Ads click identifier stored as an optional advertising cookie, and an OpenReplay session-replay cookie, the last two on the vendor's own marketing site rather than in the widget path: Minor. Pricing is the most accessible in the category, starting at €8 per month for 1,000 verifications and one website, then Advanced at 36 EUR (10,000 verifications, 5 websites) and Team at 168 EUR (50,000 verifications). Best fit: German and EU teams that want a cheap, EU-hosted, non-profiling CAPTCHA and can live without published compliance documents.
Advertising conversion tracking on the vendor's own marketing site (optional cookie, stores the gclid)
Session replay on the vendor's own marketing site (optional analytics cookie)
Card payments and billing
Infrastructure hosting (Nuremberg; determined from live infrastructure, not named by the vendor)
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Google Ireland Limited (Google Ads) | Ireland | Advertising conversion tracking on the vendor's own marketing site (optional cookie, stores the gclid) | US |
| OpenReplay | United States | Session replay on the vendor's own marketing site (optional analytics cookie) | US |
| Stripe Payments Europe Ltd. | Ireland | Card payments and billing | US |
| Hetzner Online GmbH | Germany | Infrastructure hosting (Nuremberg; determined from live infrastructure, not named by the vendor) | EU |
MIT-licensed proof-of-work CAPTCHA from Brno (BAU Software s.r.o.) with a public DPA and EU-only Cloud endpoints, though the Cloud itself runs on AWS.
Invisible proof-of-work form spam filter (Formspark team), free to 1,000 challenges a month, with a published sub-processor list that is mostly American and no legal entity named.
Vienna CAPTCHA (Captcha GmbH, part of the Krone Multimedia group) with named processors, from 8.90 EUR/month, but the site itself runs on AWS CloudFront and Google analytics.