Holding contacts nobody approved creates risk without value. Why deleting unreviewed contacts after ninety days is the right default.
Data minimization is one of the core principles of GDPR: hold only the personal data you need, for only as long as you need it. For a contact discovery tool, that raises an obvious question. What happens to contacts that are found but never reviewed?
A contact that nobody has approved has no business purpose yet. Holding it indefinitely creates a growing store of personal data with no use, which is exactly the kind of store data protection authorities object to. It also turns a privacy tool into a pressure tool, if employees are nagged to review or lose access.
If ignoring contacts triggers pressure, employees approve things just to make the reminders stop. That undermines the whole point of approval. A silent deletion keeps approval meaningful: an employee releases a contact because they want to, not because they were chased.
In RelationLens, anything nobody acts on is deleted after ninety days, silently, with no consequence to the employee and no reminder telling them to review or lose it. The customer's administrator controls how long anything is kept, on one screen with no code and no ticket.