Small businesses in the EU get two conflicting instructions at once: GDPR's data minimisation principle says don't keep personal data longer than necessary, while tax law in most member states requires invoices and accounting records to be kept for years — typically four to six, depending on the country. Neither rule is optional, and neither one tells you, in practice, what to do with the actual PDF sitting in your inbox. This is a general overview, not legal advice — check the specific retention period that applies in your country and sector.
The two clocks running at once
Personal data — a client's name and address on an invoice, an employee's payslip — falls under GDPR's minimisation principle: keep it only as long as you have a real, stated purpose for it. Accounting and tax records fall under separate retention obligations that usually run much longer, precisely because tax authorities need to be able to audit past years. In practice, the tax retention period almost always wins for anything that's also an accounting document — an invoice is personal data and a tax record at the same time, and you keep it for the tax period, not the shorter GDPR minimum.
Where this actually goes wrong
The compliance risk in most small teams isn't a deliberate decision to keep data too long — it's an inbox nobody's looked at in two years, with contracts, ID scans, and old invoices scattered across someone's personal Google Drive because that's where they happened to save them the day they arrived. Nobody can say what's in there, which is precisely the problem: you can't apply a retention policy to documents you can't find, and you can't answer a data subject access request quickly if the same invoice might be in three different places under three different names.
What actually helps: predictable filing, not automatic deletion
Findest doesn't decide your retention policy for you, and it doesn't auto-delete anything from your cloud storage on a schedule — that decision, and the legal responsibility behind it, stays yours. What it does is remove the reason your filing becomes inconsistent in the first place: every attachment goes into the same folder every time, named the same predictable way, in your own Google Drive, OneDrive, or Dropbox rather than scattered private storage. A retention policy you actually apply — "delete everything in Invoices/2019 now that six years are up" — only works if everything from 2019 is actually in Invoices/2019.
What Findest itself stores, and for how long
Findest keeps a temporary copy of each attachment in private, per-user storage hosted in the European Union, only for as long as it takes to classify and file it (and briefly afterward, so a failed upload can be retried without asking you to resend the email). You can delete that temporary copy from your dashboard at any time. The permanent copy — the one your retention policy actually governs — lives in your own cloud storage, under your own account, from the moment it's filed. See Security for the full breakdown of what's stored where.
Read-only access, not another data processor to worry about
Connecting Gmail or Outlook gives Findest read-only access to find attachments that match your rules — never write access to your mailbox, and mail that doesn't match anything is never stored at all. Revoking access at any time from Connections is immediate.