1. Purpose and Relationship to Governing Documents
This Document Retention Policy ("Policy") is published by VA WORKS, LLC ("Consultant") and forms part of the Governing Policies referenced in the Master Service Agreement (MSA), the MSA Terms and Conditions (https://vaworks.com/MasterServiceAgreement), and any applicable Scope of Work Terms and Conditions (https://vaworks.com/SOWSelection). In the event of conflict, priority shall be determined in accordance with the MSA.
The purpose of this Policy is to establish clear standards for the retention, storage, and secure disposal of records created or maintained by Consultant in connection with client services.
2. Scope
This Policy applies to all records maintained by Consultant in the course of business, including physical documents, electronic records, and communications created or received in connection with client services. It does not apply to documents or data stored within Company-provided systems, virtual desktops, or licensed platforms, which remain under Company's sole control.
3. Retention Standards
Consultant retains documents only as long as necessary to fulfill contractual, legal, or regulatory requirements. Unless otherwise required by law or client agreement:
- Administrative and service-related records are retained for three (3) years from the date of creation or engagement termination.
- Background check documentation is retained for three (3) years or longer if required by applicable law.
- Financial and invoicing records are retained for seven (7) years in compliance with U.S. tax and accounting regulations.
- Records containing Non-Public Personal Information (NPI) are retained only as long as strictly necessary to fulfill the engagement and are securely destroyed thereafter.
4. Storage and Security
- All records are stored securely, with access restricted to authorized Consultant personnel.
- Electronic records are encrypted where applicable.
- Sensitive client-related documents are not stored on local devices but are maintained within Consultant's secure internal systems, separate from Company-controlled environments.
5. Paperless and Printerless Environment Disclaimer
Consultant operates a paperless and printerless work environment. Employees and independent contractors engaged by Consultant do not print, physically copy, or retain paper records of client information. All work is performed electronically within secure systems. Any physical printing, storage, or handling of client records is the sole responsibility of the Company.
6. Disposal of Records
At the end of the retention period, records are disposed of securely to prevent unauthorized access. Secure disposal methods include shredding of paper records (if any exist) and digital deletion with certified data wipe protocols.
7. Client Systems Disclaimer
Where records exist exclusively within Company-provided systems (such as virtual desktops, licensed applications, or third-party platforms), Consultant does not own, manage, or control such environments. In accordance with the Data Security and Breach Disclaimer, Company remains solely responsible for document retention, archiving, and disposal of records created within its own systems.
8. Review Cycle
This Policy is reviewed annually by Consultant's leadership or sooner if required by regulatory changes, client requirements, or contractual obligations.
