← All guides

Brevo Forms: CAPTCHA means additional third-party processing

Before activating

check whether honeypot, double opt-in and server-side rate limits already sufficiently cover bot protection.

Brevo recommends CAPTCHA against bot logins and offers Google reCAPTCHA or Cloudflare Turnstile. For “We don’t save!” This is not a purely local protective measure. Before use, check whether honeypot, double opt-in and server-side rate limits are sufficient; otherwise make the selected third-party processing transparent.

Check after the change

Check browser memory and network requests and also view web server, proxy, application and provider logs separately. A single product setting does not automatically cover the entire processing chain.

Basis

General principles on necessary form fields, local spam defense and separate logging can be found in Contact form without tracking and unnecessary IP storage.

Reset

If the reduced configuration affects a required function, restore only the relevant setting and then recheck data flow, storage, retention and third-party connections.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑