Trust
Client documents for agencies: minimum retention that actually sticks

Agencies drown in client PDFs, brand kits, and scan packets long after a project ends. A minimum retention rule tells you what to keep, what to delete, and what never belongs in a public converter. Write the rule for working files, delivery archives, and third-party tools separately. Toolsy can help with one-off conversions under its Privacy Policy, but it is not a document retention product, a BAA vendor, or a HIPAA system. Prefer offline or contract-backed processors for privileged client material. For embed-style OCR on a client’s site, see Web agencies & integrators.
Why agency folders balloon after launch
A typical web project accumulates proposals, signed statements of work, brand PDFs, content drafts, form exports, and “final_v7” ZIPs in Slack. Nobody owns the delete button after launch. Six months later you still have passport scans from a KYC detour and a spreadsheet of customer emails from a migration dry run.
Search queries around agency client data handling rarely want a product pitch. They want a workable floor: how long to keep what, and how to stop the pile from becoming an accidental archive of other people’s secrets.
Retention without a named owner fails. Partners leave. Hard drives get cloned. A “keep everything forever” culture feels safe until a laptop theft or a subpoena turns that culture into exposure.
This post stays practical. It is not legal advice and not a substitute for counsel who knows your contracts and jurisdiction.
What “minimum retention” should mean on an agency desk
Minimum retention is the shortest period you will keep a class of file for business, tax, or contractual reasons. It is not the longest time the file can sit on a shared drive. Those two numbers get confused constantly.
Working copies versus delivery archives
Working copies are editable drafts, scratch OCR text, and staging dumps. Keep them only while the ticket is open, then delete or overwrite. Delivery archives are what you agreed to store: signed PDFs, approved brand kits, launch assets the client may request again.
Put archives in a controlled location with access lists. Keep working copies on personal machines out of that vault. When someone dumps both into the same Dropbox folder, you lose the minimum.
Calendar triggers beat “someday”
Pick triggers you can calendar: project close + 30 days for working copies; invoice paid + N years for financial records if your accountant requires it; contract end + the period your MSA names for deliverables. Write the number. Vague “keep while useful” language never triggers a delete pass.
Revisit the schedule yearly. Tools change. Clients change. The folder names do not update themselves.
Contract language that blocks random online tools
Many MSAs and DPAs require named processors, restricted locations, or a written approval before cloud OCR. A public freemium converter you found in search results usually fails that bar even when its consumer privacy page looks clear.
Data processing agreements versus upload boxes
A DPA names roles, subprocessors, and retention. An upload box on a marketing site offers convenience. Treat them as different products. If your client’s security questionnaire asks for a BAA or HIPAA attestation, Toolsy does not provide one. Say so early rather than discovering it mid-audit.
Agency work often mixes low-risk assets (public blog images) with high-risk packets (unsigned NDAs with personal data). Split the workflow. Public assets can use short-lived converters when policy allows. High-risk packets stay offline or move through a vendor your legal team already approved.
Who pays and who owns the account
The web agencies solution path is built so a client can run OCR on their own account via widget or API. That model keeps billing and quota on their side. It does not turn Toolsy into your firm’s records management system. You still need an internal policy for the files you hold after the engagement.
A practical retention checklist for client documents
Run this once per quarter on active clients, and once at project close.
- Inventory classes. Contracts, identity scans, analytics exports, creative masters, OCR drafts, chat ZIPs.
- Map each class to a keep window. Working, delivery archive, or delete-now.
- Name an owner. Project lead or ops, not “the Slack channel.”
- Separate client-owned originals from your copies. Prefer returning or deleting extras at closeout.
- Strip EXIF on photos you keep for portfolios. Location tags hitchhike on phone shots; use strip EXIF before you publish case-study images.
- Ban shadow folders. No second “backup” on a personal iCloud for the same client PII.
- Log third-party tools used. Converter, OCR, AI summary. Match them to contract approvals.
- Delete on the calendar date. Soft delete is not enough if trash syncs forever.
Teams that skip step 7 rediscover uploads during a security review. Keep a short internal list of allowed tools and the date legal last reviewed them.
When Toolsy fits and when it does not
Toolsy processes uploads for the job you run and designs them to be discarded shortly afterwards (typically within about one hour). It does not use uploads to train its own models. OCR and some AI features may still send content to OpenRouter and underlying model providers for that request. Details live in the Privacy Policy. Sibling deep dive: Is it safe to upload documents to online converters?.
Jobs that often fit
Public or low-sensitivity PDFs you already cleared for cloud processing. Markdown extraction for a knowledge base built from approved docs via PDF to Markdown. Merging non-sensitive packets when checklist items pass in Merge PDF online security checklist.
Jobs that usually do not
Unredacted KYC packs, health data, sealed litigation files, live credentials, or anything your MSA forbids on consumer tools. Prefer offline software or a contracted processor. For privilege-heavy OCR questions, see OCR for lawyers: confidentiality basics.
Toolsy is also not a long-term client file store. Do not treat activity history as an archive. History may keep metadata such as tool used and filename for a limited window; it is not a vault of full file bodies.
Browser tools versus uploads on agency machines
Some Toolsy utilities run in the browser without sending the paste to a server. Others must upload. The difference matters when a junior designer “just converts one PDF” on a client laptop. Teach the team to read the product page for that tool before they drop files.
The explainer Browser-based vs cloud AI: what leaves the device maps the split. Pair it with What happens to files on Toolsy after processing when someone asks how long bytes stick around.
If policy says no cloud AI for client content, do not look for a loophole in a free tier. Follow the written rule.
Closeout ritual that shrinks risk
At project close, schedule a one-hour closeout. Return credentials. Confirm the client has masters they need. Delete working OCR drafts and scratch Markdown. Move only the contracted delivery set into the archive location. Remove the client from shared drives that still sync to departed freelancers.
Photograph-heavy handoffs need a second pass for GPS and device tags. Portfolio posts should use cleaned images. Keep unredacted identity scans out of the case-study folder entirely.
When you must convert one more PDF after closeout, use a redacted or public copy. Prep habits before OCR are covered in Redaction before OCR: what to black out.
Limits you should put in writing
Put three sentences in your internal wiki: Toolsy (and similar consumer tools) are not HIPAA/BAA products; uploads for OCR may reach model providers for the request; retention for your client archive is your problem, not the converter’s discard timer. Link the privacy and document safety hub for the broader map. For client or marketplace vendor forms that paste GDPR language, keep GDPR-ish questions for US small business tools beside the SOP.
If a client demands certifications you cannot show, escalate to legal before the first upload. Speed is not worth a contract breach.
Frequently asked questions
How long should a web agency keep client documents?
Keep working copies only while the project needs them, then delete. Keep delivery archives for the period your contract, tax advisor, or insurer requires. Those windows differ by file class, so write a short table instead of one forever number. This is operational guidance, not legal advice for your state or country.
Does Toolsy offer a BAA or HIPAA compliance for agencies?
No. Toolsy does not claim HIPAA certification or offer a business associate agreement for agency workflows. Its Privacy Policy is written in a UK GDPR framing for a consumer and SMB product set. If your client requires a BAA, use a vendor that contracts for that relationship.
Can we upload client contracts to online OCR tools?
Only when your contract and internal policy allow that processor. Many agencies forbid consumer OCR for unsigned deals, personal data, or sealed exhibits. When policy allows a short conversion, read retention and subprocessors first, then prefer a redacted copy. See Is it safe to upload documents online?.
What is a simple minimum retention policy template for freelancers?
List file classes, keep windows, owners, and delete triggers in one page. Example rows: working drafts (close + 14 days), signed SOW (contract end + N years per counsel), portfolio images (indefinite after EXIF strip), identity scans (return or delete at close). Review the page every year with whoever owns ops.
How does Toolsy retention differ from my agency archive?
Toolsy’s upload discard target (typically about one hour after processing) covers their job storage, not your Google Drive. Your archive still needs access control, backup policy, and deletion dates. Do not assume a converter’s short window cleans up copies you downloaded and re-uploaded elsewhere.
Should client-paid OCR widgets change our retention rules?
They can reduce your middleman billing, as described on Web agencies & integrators, but they do not erase files already on your disks. Widget traffic on the client’s account still needs the client’s own privacy posture. Your internal retention checklist stays in force for anything you stored during build.
Is merging client PDFs online safe for agencies?
Sometimes, for low-sensitivity packets when HTTPS, retention language, and contract approval check out. Use the steps in Merge PDF online security checklist. Skip public merge tools for KYC bundles and privileged correspondence.
What should we strip before publishing case studies?
Remove confidential figures, unpublished URLs, and personal data. Strip photo location metadata with strip EXIF before public pages. Prefer screenshots of sanitized staging, not production databases. When in doubt, ask the client to approve the asset list in writing.
Do browser-based tools avoid all privacy risk?
No. They reduce server retention for that paste, but you still trust the JavaScript the site ships and any account you create. Cloud OCR and document conversion still upload when the product requires a server. Classify tools before juniors run them on client laptops.
Where do we read Toolsy’s binding privacy text?
The Privacy Policy controls. Blog posts summarize; if wording conflicts, the policy wins. For a map across trust topics, start at Privacy and document safety.
For legal-matter OCR caution, continue with OCR for lawyers: confidentiality basics. For blacking out fields before any upload, see Redaction before OCR.
Read the Privacy Policy
Binding text for upload discard targets, processors, and what Toolsy does not claim. No BAA or HIPAA certification.


