As enquiries accumulate you end up with a contact list. To a marketer that is plainly an asset. The same list is also personal data — and holding it comes with a duty to protect it.
That duty does not scale with your size. Incidents happen at sites taking a handful of enquiries a month, and “we are only a small company” explains nothing afterwards. Happily, the working principles are simple: collect less, set a period, delete.
1. Collect only what you need
There is one test for a form field: is it needed to start this conversation? Company size, budget band and industry may be useful later, but they are not needed at first contact.
Collecting less is a privacy principle and a conversion tactic at the same time. Fewer fields make submission easier, and they shrink what you have to defend. Data you never collected cannot leak — the most reliable protection there is.
2. Decide the retention period up front
This is where most sites stall. No period was ever set, so everything stays for ever: an enquiry from three years ago sits in the database, in a mailbox, and in somebody’s spreadsheet.
The period comes from your actual sales cycle — longer where decisions take months, shorter where they take an afternoon. What matters is not the number but that a number exists, and that it appears in your privacy policy where customers can read it.
Decide in advance what happens when someone asks to be deleted. With a route to receive the request and a deadline to act on it, that request becomes a procedure rather than an emergency.
3. Count the copies before you delete
Deletion is hard for one reason: copies exist in several places. The form plugin stores a record in the database, the notification sits in a mailbox, someone pasted it into a spreadsheet, and it may have been uploaded as a customer list to an ad platform. Clearing the database leaves the other three untouched.
So the work starts with an inventory, not a deletion. Writing down those four lines for your own setup is enough to make everything afterwards possible. And if your form plugin is configured to store submissions in the database, check whether that storage is needed at all — when the notification mail already arrives, it is often a duplicate you are now obliged to protect.
The technical measures that protect stored personal data are covered in the Security archive, and a review covering access, backups and vulnerabilities together is part of the diagnostic in our optimization program.
Next part
With collection decided and protection in place, what remains is what you do after a lead arrives. The next part is the follow-up flow, where response time moves conversion more than most funnel tweaks do.