Somebody filled in your contact form last night. A name, a phone number, an email address, and one box where people always write more than you asked for: an address, a flat number, what is broken at home, sometimes something touching on their health or their money.
They pressed send. Where did it go?
Most owners can answer half the question: "into my mailbox." The other half - who else got a copy, and how long it stays somewhere - usually ends in a pause.
One honest note first: this is not legal advice, and every business differs. But this part is out of shape in the same way on almost every small Estonian website, and you can check it yourself in half an hour.
A form is a small database nobody looks after
One submitted form usually produces three copies, not one.
- The message in your mailbox. The only one most owners know about.
- A record in the site's own database. A great many form setups also save the submission to the site, so that no enquiry is lost if the email fails. A useful feature. Except that nobody ever opens that list, and there are now three years of people in it.
- A copy at the service provider. Sending the mail almost always runs through somebody else: a sending service, a newsletter tool or a form service. They have their own logs and their own retention period.
None of those three is bad in itself. What is bad is knowing about only one of them. The answer to "where is my data" cannot be "I do not know where my data is", and that is the only question anybody will ever ask you about it.

Four questions your form has to answer
Not for a lawyer. For you, because without the answers you cannot write a privacy page that is true either.
1. What are you asking for, and why? Every field has to earn its place. A contact form asking for an ID number, a date of birth or an address before it is even clear whether you will work together is collecting things whose safekeeping is now your problem. If you cannot say what you will do with that field tomorrow, you do not need the field.
2. Where does it go? The three places above. Write them down for yourself, by name, with the services named. That list is the foundation of all the rest of the work.
3. How long do you keep it? "As long as necessary" is not an answer, it is the sentence you write when you have no answer. An answer is "two years", or "until the quote is done, and a year after that". Any specific period beats any general one.
4. Who has access? The info mailbox whose password four people know, two of whom no longer work here. The phone that always sits unlocked on the desk. The former marketer's account nobody closed. Access is where most small companies actually leak, and it is not a technical attack, only an uncatalogued list.
The checkbox with nothing behind it
Almost every form carries the line "I consent to the processing of my personal data" with a tick box in front of it. The link usually leads to a privacy page that says neither where the data goes nor how long it is kept.
Two different things are bundled together here. When somebody writes to you of their own accord to ask for a quote, replying to them and preparing that quote is not usually the situation where consent is what you are relying on - that is what they came for. Consent is a separate thing, and you genuinely need it when you want to send them something else later: a newsletter, a campaign, a reminder.
Which is why one tick box covering everything at once does less than it promises. It does not earn you the newsletter, because nobody understood they were subscribing. And it does not help with the reply either, because there was no problem there. What helps is two separate things: one short sentence about what you do with this enquiry, and a separate, unticked box for the newsletter alone. The same logic as the cookie banner: consent is an act, not a box.
Three places where data quietly piles up
The mailbox nobody clears. Six years of enquiries, job applications with CVs attached, photographs of broken things inside people's homes. A mailbox feels personal, and so it does not feel like an archive. It is an archive.
The old site's database. The site was rebuilt two years ago. The old one stayed on the server, because "you never know". The form table is still in it. Nobody updates that server and nobody remembers there is data on it.
Forwarding. At some point the form mail was also sent to a private address, so it would be easier to read on a phone. That setting stayed. There is now a third copy in a mailbox that does not belong to the company. The same setting is also why form mail goes missing; why a message never arrives is a story of its own.

Deleting is a feature, not a promise
Your privacy page says data is kept only as long as necessary. That sentence is a promise. A promise assumes somebody can actually delete.
Try one thing that takes five minutes: find an old enquiry in your mailbox and think through what you would do if that person asked tomorrow to have their data erased. Where would you look? Who knows there is also a copy in the site's database? Does anybody remember the third place?
If the answer is "I would search a bit and hope I found it all", the promise on the page is not false out of bad faith. It was simply written before anybody thought about keeping it.
The practical fix is boring and it works: one person who knows all three places, and one repeating entry in a calendar. Fifteen minutes, twice a year. Delete what no longer has a reason to exist, and check who still has access to the mailbox.
And here it meets the sales side
So far this has been about what is right. Now the part that matters even to a reader with no interest in compliance.
A form asking for nine things collects half as many enquiries as one asking for three. Every extra field is one more reason not to fill it in, and on a phone that reason carries more weight than it does on a desktop. The field you remove for legal reasons is the same field that stopped the reader.
This is one of the rare places where both answers point the same way. Ask for less. Say in one sentence what happens to the enquiry next. Reply quickly. Delete what is no longer needed. None of those four is a sacrifice made to compliance: all four also produce more enquiries. The remaining obstacles between a reader and an enquiry are written out here.
Half an hour this week
- Fill in your own form from a phone, with real details. Count the fields, and ask of each one what you will do with it tomorrow.
- See where the message landed and go looking for the second copy: check whether the site saved it as well.
- Ask your developer one question: which service sends my form mail, and how long does it keep it.
- Review who has the mailbox password. Including the people who no longer work here.
- Read your privacy text as a stranger would. If it does not name three places and one period of time, it is not about your site.
- Put a repeating entry in the calendar, twice a year. Without it this article stays a good intention.
If you would rather somebody else went through it and wrote down what actually happens on your site, that is what a compliance audit is for. And if nobody in the building has time to think about forms, mailboxes and updates, that is exactly what a maintenance service is.
The messages in your mailbox are information about people, given to you because of one question. Most of it is no longer needed. The only thing keeping it there is that nobody has ever decided to throw it away.
Frequently asked questions
One submitted form usually produces three copies. The message arrives in your mailbox, a great many form setups also save the submission into the site's own database, and the sending itself runs through a third-party service with its own logs and its own retention period. Most owners know about one of them. Write all three down by name: without that list you cannot write a privacy page that is true either.
The exact period depends on what you need the data for, but what matters is that a period exists and is specific. "As long as necessary" is the sentence you write when you have no answer. Choose something measurable, such as two years, or until the quote is done plus one year after, and spend fifteen minutes twice a year clearing up. Without a repeating calendar entry, a retention period stays a promise nobody keeps.
When somebody writes of their own accord to ask for a quote, replying to them is not usually the situation where consent is what you rely on: that is what they came for. Consent is genuinely needed when you want to send them something else later, such as a newsletter. One tick box bundling both together therefore does less than it promises. What works is two separate things: a short sentence about what happens to the enquiry next, and a separate, unticked box for the newsletter alone.
As few as it takes to reply. Every extra field is one more reason to abandon the form, and on a phone that reason carries more weight than on a desktop. Ask of each field what you will do with it tomorrow: if there is no answer, the field is not needed. An ID number, a date of birth and an address before any work has started are the usual failures of that test. The field you remove for legal reasons is generally the same one that stopped the reader.
Read next

The bar at the bottom of the page is not where consent happens. Seven mistakes we see on almost every site, and how to check for them yourself in ten minutes.