Privacy & POPIA
Keno Forms is built data-minimising by default. It stores the lead you actually collect, and nothing you did not ask for. That keeps you on the right side of South Africa's POPIA (and the EU's GDPR, which works the same way here).
What is stored by default
For every submission Keno Forms saves:
- the field values the visitor entered,
- the source context it detected (page URL, title, referrer, first-touch UTMs),
- the campaign source and an internal spam score.
It does not store the visitor's IP address or browser user-agent. There is nothing to strip later and nothing extra to justify in a data-processing record.
The consent checkbox
The default form includes a "Keep me updated by email" checkbox. Marketing list opt-in (Mailchimp, Brevo, Resend Audiences) only runs when that box is ticked, so a lead is never added to a mailing list without explicit consent. You can relabel or remove the checkbox in the form builder, or make it required for forms where consent is mandatory.
Storing IP and user-agent (opt-in)
Some businesses need the IP address and user-agent for audit or fraud reasons. If you do, enable Store IP address and user-agent with each entry under Keno Forms > Settings > Security & privacy. Only turn this on if you can justify it under POPIA / GDPR, and reflect it in your privacy policy. It is off until you choose otherwise.

Data ownership and erasure
Every lead lives in your own WordPress database as a private "Form entry", so you own the data outright. To honour an erasure request, delete the relevant entry from Keno Forms > Form entries. To take a full copy for a data-subject access request, use the CSV export.