This is Neuroscale’s authoritative records-retention schedule. It governs how long records are retained and when they are disposed of, regardless of where they are stored. It implements the Data Management Policy and supersedes the placeholder in the Data Retention Matrix (which is system-by-system; this schedule is record-type-by-record-type).
A litigation hold, regulatory hold, or government investigation overrides every period in this schedule. See Legal holds below.

How to read this schedule

Each row identifies a record type, the retention period (and where the period starts running), the source / authority for the period, the owner (who is accountable that disposal happens or that the record is kept long enough), and the storage location for the canonical copy. Where multiple sources apply, Neuroscale follows the longest required period.

Schedule

Corporate

Record typeRetentionSource / authorityOwnerStorage location
Articles / Certificate of Organization, operating agreementPermanentVirginia Limited Liability Company Act (Va. Code §§ 13.1-1000 et seq.); corporate hygieneCFOMicrosoft SharePoint — Corporate folder; counsel’s office
Board / member resolutions and minutesPermanentBest practice; potential audit and litigation evidenceCFOSharePoint — Corporate
Stock / unit ledger and cap-table recordsPermanentVa. Code § 13.1-1028 (member inspection rights); tax basisCFOCap-table tool of record + SharePoint
Equity grant agreements (option / RSU / profits-interest)Life of grant + 7 years post-exercise/cancellationTax basis (IRC §6501); IRS look-backCFOCap-table tool + SharePoint
Commercial contracts (customer, vendor, partner) — executed7 years from expiration or terminationStatute of limitations on contracts (UCC §2-725 / state long-arm 4-6 yrs + buffer)General CounselSharePoint — Contracts
NDAs7 years from expirationSame as aboveGeneral CounselSharePoint — Contracts
Tax returns and supporting workpapers7 years from filingIRC §6501(a) (3 yrs default), §6501(c)(1), §6501(e) (6 yrs for substantial omission); +1 bufferCFOAccounting system + SharePoint
Audit reports (financial) and audit workpapers7 yearsSOX §802 / 18 U.S.C. §1520 (applies to public companies and audit firms; followed as best practice)CFOSharePoint — Finance
Insurance policiesUntil expiration + 7 yearsLong-tail claims; limitations periodsCFOSharePoint — Insurance
Filed regulatory submissions (state, federal)PermanentAudit / regulatory inquiryGeneral CounselSharePoint — Compliance

Customer data (Neuroscale as processor)

Record typeRetentionSource / authorityOwnerStorage location
Customer-account configuration and metadataLife of contract + 60 days post-terminationCustomer DPA template; customer-controlled deletionEngineering LeadAWS (production DB — RDS / Aurora) and Vultr (Postgres) — per workload routing
Personal data of customer end usersPer Customer DPA template; default = match the customer’s documented instruction; default deletion 60 days post-terminationCustomer is controller; Neuroscale is processor (GDPR Art. 28; CCPA service-provider terms)Engineering LeadAWS (production DB — RDS / Aurora) and Vultr (Postgres) — per workload routing
Customer support tickets, recordings, and transcripts3 years from ticket close (default)Reasonable business need; matches contract limitations periodCTOSupport tool of record
Customer account-deletion confirmations7 yearsAudit evidence of fulfilled deletion obligationsEngineering LeadSharePoint — Compliance

Personnel records (Neuroscale employees, contractors, applicants)

Neuroscale follows the longest of the federal floor, state floor (e.g., California adds 4 years on top of FLSA for some categories), and contract.
Record typeRetentionSource / authorityOwnerStorage location
Job applications, resumes, interview notes (for unhired applicants)1 year from application or last actionEEOC regs 29 C.F.R. §1602.14; Title VIICHROHRIS / ATS
Hiring records for executives and roles ≥ 100 employees subject to OFCCP2 yearsOFCCP / 41 C.F.R. §60-1.12CHROHRIS / ATS
I-9 employment-eligibility forms3 years from hire date OR 1 year after termination, whichever is laterINA §274A; 8 C.F.R. §274a.2(b)(2)CHROHRIS (separate I-9 vault)
Personnel file (offer letter, agreements, performance, training, discipline)Term of employment + 7 yearsEEOC, Title VII, ADEA (3 yrs); IRS (4 yrs); NLRA; CA Labor Code §1198.5 (3 yrs post-termination — federal floor extended for risk)CHROHRIS
Payroll records (FLSA-covered)3 yearsFLSA 29 C.F.R. §516.5CFOPayroll system
Time cards, wage-rate schedules, work schedules (FLSA supplementary)2 yearsFLSA 29 C.F.R. §516.6CFOPayroll system
FMLA records3 yearsFMLA 29 C.F.R. §825.500CHROHRIS (separate FMLA file)
ADA reasonable-accommodation recordsLife of employee + 7 yearsADA + medical-records best practice; kept separately from personnel fileCHROHRIS (confidential medical file, separate)
Workplace-injury / OSHA Form 300, 300A, 301 logs5 years following the year covered29 C.F.R. §1904.33CHRO + CISOHRIS / SharePoint
Workers’ compensation claimsPer state — generally life of claim + 5 years (CA), longer in some statesState workers’-comp statutesCHROHRIS / SharePoint
Benefits plan documents, summary plan descriptions, Form 55006 years from filingERISA §107 (29 U.S.C. §1027)CHRO + CFOSharePoint
Participant-level benefits recordsLife of participant + 6 yearsERISA §209; ERISA §107CHROBenefits provider system
Payroll-tax records (W-2, W-4, 1099)4 years after the tax due / paid dateIRC §6001; 26 C.F.R. §31.6001-1; IRS Pub. 583CFOPayroll / accounting system
Equal Pay Act records3 yearsEPA / 29 C.F.R. §1620.32CHROHRIS
Training records (Vanta LMS)Term of employment + 7 yearsPersonnel record best practiceCHRO + CISOVanta

Background checks and consumer reports

Record typeRetentionSource / authorityOwnerStorage location
Pre-employment background-check report (Checkr)5 years post-hireFCRA §1681; reasonable retention for the action takenCHROCheckr + HRIS
Pre-adverse-action and adverse-action notices and supporting reports5 years from notice dateFCRA §1681m; statute of limitations for FCRA private actions (2/5 yr)CHROHRIS — confidential file
Applicant disclosure-and-authorization formsTerm of employment + 5 years (or 5 years from decision for unhired applicants)FCRA §1681b(b)(2)CHROHRIS / ATS

Financial records

Record typeRetentionSource / authorityOwnerStorage location
General ledger, journals, trial balances7 yearsIRS / SOX best practiceCFOAccounting system
Accounts payable / receivable records, invoices7 yearsIRC §6501; UCC §2-725 (4 yrs) + bufferCFOAccounting system
Bank statements, reconciliations, cancelled checks7 yearsIRS; banking-secrecy regulations (BSA / 31 C.F.R. §1010.430 — 5 yrs)CFOAccounting system + bank portal
Audit workpapers (external)7 yearsSOX §802 best-practiceCFOAuditor + SharePoint
Expense reports and supporting receipts7 yearsIRC §274; §6001CFOExpense tool + accounting
Fixed-asset recordsLife of asset + 7 yearsIRC depreciationCFOAccounting system
Record typeRetentionSource / authorityOwnerStorage location
Marketing-consent records (opt-in proof)Until consent is withdrawn + 3 yearsGDPR Art. 7(1) — proof obligation; CAN-SPAM enforcement (5-year claims period)Marketing (Hanna Gillas)Marketing automation
Suppression / unsubscribe listsIndefinite (must persist to honor opt-outs)CAN-SPAM 16 C.F.R. §316.5 — must retain to enforceMarketing (Hanna Gillas)Marketing automation
Cookie / consent-banner choicesUntil withdrawn + 3 yearsGDPR proof; ePrivacy DirectiveMarketing (Hanna Gillas)Consent-management platform
Lead and prospect recordsWhile active + 3 years from last engagementReasonable business needCEO (until a commercial lead is hired)HubSpot

Security and operations

Record typeRetentionSource / authorityOwnerStorage location
Security event logs (Better Stack + CloudWatch)Minimum 12 months online; archived per AWS lifecycle thereafterSOC 2 CC7; ISO 27001 A.8.15CISOBetter Stack; CloudWatch
Authentication / access logs12 monthsSame as above; see Operations Security — Logging & MonitoringCISOBetter Stack / Rippling
Vulnerability scan results (Detectify, Dependabot, Snyk, Semgrep)1 year for findings; current state indefiniteSOC 2; ISO 27001 A.8.8CISOTool of record
Penetration-test reports7 yearsAudit evidence; insuranceCISOSharePoint
Incident records and post-mortems6 yearsSOC 2 evidence; GDPR audit windowCISOSharePoint — Compliance
Material-incident records (regulatory-reportable)PermanentLitigation likely; regulatory recordCISO + General CounselSharePoint — Compliance
Change-management records (GitHub, deploy logs)3 yearsSOC 2 CC8; audit windowEngineering LeadGitHub / CI logs
Access-review evidenceAt least 1 year (see Access Reviews)SOC 2 CC6CISOSharePoint — SOC 2 evidence

Privacy program records

Record typeRetentionSource / authorityOwnerStorage location
DSR / DSAR records (request, verification, response, evidence of action)6 years from closureGDPR audit window; state-law audit windowsGeneral CounselDSR tracker
DPIAs / PIAs6 years from end of underlying processingGDPR Art. 35 audit evidenceGeneral Counsel + CISODPIA register
Cross-border transfer records — signed SCCs, UK Addenda, IDTAs, DPF self-certificationsLife of agreement + 6 yearsGDPR Chapter V; auditGeneral CounselSharePoint — Privacy
Transfer Impact Assessments (TIAs)6 yearsGDPR; Schrems II auditGeneral Counsel + CISOSharePoint — Privacy
Records of Processing Activities (ROPA)6 years from last updateGDPR Art. 30General CounselSharePoint — Privacy
Government / law-enforcement data-access requests received and responsesPermanentLitigation evidence; transparency obligationsGeneral CounselSharePoint — Privacy (restricted)

Vendor records

Record typeRetentionSource / authorityOwnerStorage location
Vendor agreement, DPA, SCCsLife of agreement + 6 yearsSOC 2; contract limitationsGeneral CounselSharePoint — Contracts
Vendor security questionnaires, SOC 2 / ISO 27001 reportsTerm of relationship + 3 yearsSOC 2 evidenceCISOVanta
Vendor risk-assessment recordsTerm of relationship + 3 yearsSee Vendor Risk AssessmentCISOVanta

System backups

Record typeRetentionSource / authorityOwnerStorage location
Production database backups60 days operational rolling, then aged out per cloud-provider lifecycle policyOperational recovery; balanced against deletion-on-request obligationsEngineering LeadAWS Backup / S3 (lifecycle) for AWS-hosted DBs; Postgres WAL archives in Vultr Object Storage for Vultr-hosted DBs (with cross-cloud copy to AWS S3 for Confidential workloads)
Object-store snapshots60 days operational; lifecycle thereafterSameEngineering LeadAWS S3 (versioning) and Vultr Object Storage (versioning) — per workload routing
Backup index / restoration logs1 yearSOC 2 CC9Engineering LeadAWS / Better Stack
Backups are excluded from immediate-deletion DSR responses; the data subject’s record is suppressed in production immediately, and the backup copy ages out on the rolling 60-day schedule. This approach is documented in our DSR responses where applicable. A legal hold (also called a litigation hold or preservation notice) overrides every period in this schedule. When the General Counsel issues a hold, custodians must preserve all in-scope records — including emails, Slack messages, documents, source code branches, and ephemeral data — until the hold is released in writing.
  • The General Counsel issues, scopes, and releases legal holds.
  • CHRO applies the hold to departing employees (no purge of mailbox or files until released).
  • IT applies retention overrides in Microsoft Purview, SharePoint, Slack, and any other in-scope system.
  • The legal-hold register lives in the Legal Holds project in Linear (restricted access) and contains: matter name, custodians, scope, issued date, last-reviewed date, release date.
  • Holds are reviewed at least every 6 months for continued necessity.

Disposal

When a record reaches the end of its retention period and is not on hold, it is securely disposed of per the Records Disposal procedure. Disposal evidence (where applicable — e.g., Certificate of Destruction for media) is itself retained per Records Disposal.

Review

This schedule is reviewed by the General Counsel + CISO at least annually, and on any material change in law (new state privacy law adopted; GDPR amendment; SEC or sector-specific rule change). Material changes are version-controlled and announced internally.

Cross-references

Version history

VersionDateDescriptionAuthorApproved by
1.0May 8, 2026Initial versionCameron WolfeIshan Jadhwani