FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. VAPTCHA

VAPTCHA

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Vaptcha do?

Vaptcha is a Chinese CAPTCHA and bot-detection service that uses behavioral analysis and gesture verification to distinguish humans from bots. When embedded on EU websites, visitor behavioral data, IP addresses, and browser fingerprints are transmitted to Vaptcha servers in China. China has no EU adequacy decision, making this a high-risk international transfer. European data protection authorities strongly recommend replacing Vaptcha with EU-hosted CAPTCHA alternatives such as hCaptcha or Friendly Captcha.

What is Vaptcha?

Vaptcha is a Chinese CAPTCHA service that uses gesture-based human verification and behavioral analysis. It is widely used in China and increasingly embedded in international websites. When loaded on EU websites, it transmits visitor behavioral data, IP addresses, and browser fingerprints to Vaptcha servers in China.

The China transfer problem

China has no EU adequacy decision. The Chinese Cybersecurity Law, Data Security Law, and National Security Law require Chinese companies to provide data access to authorities upon request. SCCs with Chinese entities are theoretically possible but practically difficult to enforce. EU DPAs including the French CNIL and German DPAs have flagged transfers to China as problematic.

Recommended alternatives

EU-hosted CAPTCHA alternatives: hCaptcha (privacy-focused, US but with EU data options), Friendly Captcha (German, EU-hosted, no personal data processing), Altcha (open-source, self-hostable), or CloudFlare Turnstile. All provide effective bot protection without China data transfers.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Practical compliance steps

Immediately replace Vaptcha with a GDPR-compliant CAPTCHA alternative. If replacement is not immediately possible: conduct a DPIA, implement consent before loading Vaptcha, attempt SCCs with Vaptcha, and document the risk assessment. Replacement is strongly recommended.

GDPR consent category

Essential

Websites using Vaptcha must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Art. 6(1)(f)) for anti-bot protection purposes may apply for strictly necessary CAPTCHA functionality. However, the China transfer and Chinese surveillance law concerns significantly complicate this. Consent (Art. 6(1)(a)) is more defensible. European privacy advocates recommend replacing Vaptcha with EU-hosted alternatives.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy, GDPR Chapter V (international transfers to China)

DPIA considerations

A DPIA is strongly recommended for Vaptcha given the China data transfer with no adequacy decision, potential exposure to Chinese intelligence law, and the processing of behavioral biometric data. Consider this a high-risk processing activity.

Sample consent text

This site uses Vaptcha for bot protection. Vaptcha processes behavioral interaction data on servers in China. Please accept to use this feature or contact us for an alternative.

Technical details

Tracking methodJavaScript CAPTCHA widget, client-side behavioral analysis, server-side verification, IP and interaction data collection
Server locationChina (Vaptcha is a Chinese CAPTCHA service)
Data transferred outside the EUVaptcha is a Chinese CAPTCHA and bot-detection service. When integrated on EU websites, visitor IP addresses, browser fingerprints, and behavioral interaction data are transmitted to Vaptcha servers in China. China has no EU adequacy decision. SCCs are required but may face compatibility challenges due to Chinese data access laws.

Third-party domains contacted

www.vaptcha.comapi.vaptcha.comcdn.vaptcha.comv.vaptcha.com

Cookies placed

NameTypeDurationPurpose
vaptcha_tokensecuritySessionStores the CAPTCHA verification token after the user completes the challenge, used for server side validation.
vaptcha_vidsecurity24 hoursAssigns a visitor identifier for behavioral analysis to distinguish humans from bots.
vaptcha_risk_scoresecuritySessionStores the computed risk score from client side behavioral analysis including mouse movements and interaction patterns.
vaptcha_langfunctionality1 yearRemembers the selected language preference for the CAPTCHA widget interface.

Vaptcha is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Vaptcha set?

Vaptcha is a human verification (captcha) service that sets cookies to distinguish legitimate users from bots. These include session tokens, risk assessment identifiers, and device fingerprint data. Vaptcha may store persistent cookies to remember verified users and reduce repeated challenges.

Is consent required to use Vaptcha?

Vaptcha occupies a nuanced position under the ePrivacy Directive. If used solely for security purposes (bot protection on login or contact forms), it may qualify as strictly necessary and not require prior consent. However, if Vaptcha sets persistent tracking cookies beyond what is needed for verification, consent may be required.

What is the legal basis for using Vaptcha?

The primary legal basis is legitimate interest under Article 6(1)(f) GDPR for protecting your website against automated abuse. For strictly necessary security cookies, Article 5(3) of the ePrivacy Directive provides an exemption. Document your legitimate interest assessment to justify why Vaptcha is needed.

Does Vaptcha transfer data to third countries?

Vaptcha is developed by a Chinese technology company, and data may be processed on servers located in China. This constitutes a transfer to a third country without an EU adequacy decision. You must implement appropriate safeguards and clearly disclose this transfer in your privacy policy.

Is a DPIA required for Vaptcha?

A DPIA is recommended for Vaptcha implementations because the service processes device fingerprints and behavioral data, involves data transfers to China (a country without an EU adequacy decision), and applies automated decision making to determine human versus bot status.

How do I implement compliance with Vaptcha?

Disclose Vaptcha's use in your privacy policy, including data transfers to China. If consent is required, integrate Vaptcha loading with your consent management platform. Consider using Vaptcha only on forms where bot protection is genuinely necessary rather than site wide. Document your legitimate interest assessment.

Are there privacy friendly alternatives to Vaptcha?

Consider EU based or privacy focused captcha solutions such as hCaptcha (with privacy options), Friendly Captcha (German company, GDPR focused), or mCaptcha (open source, self hosted). These alternatives process data within the EEA and minimize tracking, reducing compliance complexity.

How do I update my cookie policy for Vaptcha?

Add Vaptcha to your cookie declaration listing all cookies it sets, including session tokens, verification identifiers, and any persistent cookies. Specify that data is processed by Vaptcha in China, state the purpose as security and bot prevention, and include cookie durations and types.