Records Retention and Destruction Policy

Effective Date: January 1, 2026

1. Purpose

The purpose of this Records Retention and Destruction Policy (“Policy”) is to establish consistent requirements for the creation, maintenance, retention, protection, and lawful destruction of records maintained by The Society of Individualized Medicine & Therapies ("SOIMT").

This Policy is intended to:

  • Ensure that SOIMT maintains records necessary for its operations, governance, legal obligations, financial responsibilities, and historical purposes;

  • Establish reasonable retention periods for different categories of records;

  • Protect confidential and sensitive information;

  • Reduce unnecessary storage of outdated or duplicate records;

  • Ensure records are destroyed securely when their retention period expires; and

  • Prevent the destruction of records that may be relevant to litigation, audits, investigations, claims, or governmental inquiries.

2. Scope

This Policy applies to SOIMT's directors, officers, employees, volunteers, contractors, consultants, and other individuals who create, receive, maintain, or manage records on behalf of SOIMT.

It applies to records regardless of format or location, including:

  • Paper documents;

  • Electronic documents;

  • Email and other electronic communications;

  • Databases and spreadsheets;

  • Financial records;

  • Accounting records;

  • Contracts and agreements;

  • Governance records;

  • Personnel records;

  • Membership records;

  • Donor and contribution records;

  • Program and event records;

  • Website and digital records;

  • Photographs, recordings, and publications; and

  • Records maintained by third-party service providers on SOIMT's behalf.

3. Definition of Records

For purposes of this Policy, a “record” is information created, received, or maintained by SOIMT that documents its activities, decisions, transactions, obligations, or operations and that has continuing administrative, legal, financial, operational, or historical value.

Not every piece of information is a record.

Examples of materials that generally do not need to be retained as official records include:

  • Duplicate copies maintained solely for convenience;

  • Transitory messages with no substantive business purpose;

  • Unsolicited advertisements or spam;

  • Drafts that have been superseded and have no continuing value; and

  • Temporary working materials that do not document a final decision or transaction.

4. General Retention Principle

SOIMT will retain records for the periods specified in the Records Retention Schedule attached to this Policy, unless a longer period is required by:

  • Applicable federal, state, or local law;

  • A contractual obligation;

  • A grant or funding requirement;

  • A regulatory requirement;

  • An audit or investigation;

  • A pending or reasonably anticipated legal claim or proceeding;

  • A preservation request or legal hold; or

  • A determination by SOIMT that permanent retention is appropriate.

Retention periods are minimum periods unless otherwise stated.

When a record falls into multiple categories, the longest applicable retention period should generally be followed.

5. Records Retention Schedule

The following schedule establishes SOIMT's standard retention periods.

Record Category

Minimum Retention Period

Articles of Incorporation / Formation Documents

Permanent

Bylaws and amendments

Permanent

IRS determination letter and tax-exempt status records

Permanent

Board and committee minutes

Permanent

Board resolutions and significant governance records

Permanent

Annual reports and organizational reports

Permanent

Historical publications and significant organizational records

Permanent

Policies and major policy revisions

Permanent

Audited financial statements

Permanent

General ledger and accounting records

7 Years

Bank statements and reconciliations

7 Years

Accounts payable records

7 Years

Accounts receivable records

7 Years

Invoices, receipts, and supporting financial documentation

7 Years

Payroll records

7 Years

Employment tax records

7 Years

Donation and contribution records

7 Years

Donor acknowledgments and substantiation records

7 Years

Grant agreements and grant financial records

7 years after grant closeout, or longer if required

Contracts and agreements

7 years after expiration or termination

Insurance policiesInsurance policies

7 years after expiration; permanent for significant claims

Legal correspondence and significant legal records

7 years after matter closes; permanent where historically significant

Litigation files

7 years after final resolution, or longer if advised by counsel

Personnel files

7 years after employment ends, subject to applicable law

Volunteer records

7 years after relationship ends

Membership records

7 years after membership ends

Program and event records

7 years after completion

Participant records

7 years after participation ends, subject to applicable law

Vendor and contractor records

7 years after relationship ends

Website terms, policies, and significant versions

Permanent or 7 years after replacement

Website operational records and routine logs

2 years

Marketing and communications records

3 years

Routine correspondence

3 years

Email with substantive business, legal, financial, or governance value

Based on applicable record category

Electronic backups

Based on applicable backup and disaster-recovery schedule

Duplicate or transitory records

When no longer needed

5.1 Permanent Records

Permanent records should be maintained in a secure format that permits future access and, where appropriate, migration to current technology.

Permanent records include organizational formation documents, bylaws, significant governance records, board minutes, major historical records, tax-exempt status documentation, and other records designated by the Board of Directors.

6. Electronic Records

Electronic records are subject to the same retention requirements as paper records.

SOIMT will make reasonable efforts to ensure that electronic records:

  • Remain accessible for the duration of the applicable retention period;

  • Can be reasonably retrieved when needed;

  • Are protected against unauthorized access or alteration;

  • Are backed up where appropriate; and

  • Are securely deleted when their retention period expires.

Records stored in cloud-based systems remain SOIMT records even when the physical infrastructure is owned or operated by a third party.

7. Email and Electronic Communications

SOIMT does not intend to retain every email indefinitely.

Employees, officers, directors, and volunteers should determine whether an email constitutes an official organizational record.

Emails documenting significant decisions, contracts, financial transactions, governance matters, legal matters, personnel matters, or other substantive organizational activities should be retained according to the applicable record category.

Routine communications may be deleted when they are no longer needed and are not subject to a retention requirement or legal hold.

8. Legal Holds

SOIMT must immediately suspend routine destruction of records when litigation, a government investigation, audit, subpoena, regulatory inquiry, claim, or other legal matter is pending or reasonably anticipated.

A “Legal Hold” may be issued by the Executive Director, Board Chair, designated records administrator, or legal counsel.

When a Legal Hold is issued:

1. All potentially relevant records must be preserved;

2. Routine deletion and destruction must be suspended;

3. Employees and other custodians must preserve relevant paper and electronic records;

4. Automatic deletion procedures affecting relevant records must be suspended where reasonably practicable;

5. Records must not be altered, concealed, destroyed, or discarded; and

6. The Legal Hold will remain in effect until authorized termination.

No employee, volunteer, officer, or director may destroy a record that is subject to a Legal Hold.

9. Record Destruction

Records may be destroyed only after:

  • The applicable retention period has expired;

  • There is no active Legal Hold;

  • There is no known pending audit, investigation, claim, or legal proceeding requiring preservation; and

  • The record is not otherwise required to be maintained.

Destruction should be performed in a manner appropriate to the sensitivity of the information.

Paper records containing confidential or personal information should be securely shredded or destroyed.

Electronic records should be securely deleted using reasonable procedures appropriate to the system and sensitivity of the information.

10. Personal and Confidential Information

SOIMT may maintain records containing personal, financial, employment, donor, membership, or other confidential information.

Such records should be accessed only by individuals with a legitimate organizational need.

SOIMT will use reasonable administrative, technical, and physical safeguards to protect confidential records against unauthorized access, disclosure, alteration, loss, or destruction.

Records containing sensitive information should not be retained longer than reasonably necessary for legitimate organizational, legal, or operational purposes.

11. Third-Party Service Providers

Where records are stored or processed by third-party providers—including accounting platforms, cloud-storage providers, payment processors, membership platforms, email providers, website hosting companies, or other vendors—SOIMT should take reasonable steps to ensure that contractual arrangements and provider practices are consistent with SOIMT's recordkeeping and information-security requirements.

When a vendor relationship ends, SOIMT should determine what records must be returned, transferred, archived, or securely deleted.

12. Responsibilities

If a factual error is identified after publication, SIMT shall promptly evaluate the concern.

When warranted, the Society may:

Board of Directors

The Board of Directors is responsible for oversight of this Policy and may approve material changes to the Policy.

Executive Director or Chief Executive

The Executive Director or equivalent organizational leader is responsible for implementing this Policy and ensuring that appropriate procedures are established.

Records Administrator

SOIMT may designate a Records Administrator to:

  • Maintain the Records Retention Schedule;

  • Coordinate retention and destruction activities;

  • Monitor compliance;

  • Coordinate Legal Holds;

  • Maintain documentation concerning authorized destruction; and

  • Recommend updates to this Policy.

Employees, Officers, Directors, and Volunteers

Individuals covered by this Policy are responsible for:

  • Maintaining records appropriately;

  • Following applicable retention periods;

  • Protecting confidential information;

  • Preserving records subject to Legal Holds; and

  • Not intentionally destroying or altering records in violation of this Policy.

13. Destruction Log

For significant records or significant batches of records, SOIMT may maintain a destruction log documenting:

  • Description or category of records destroyed;

  • Date of destruction;

  • Applicable retention period;

  • Method of destruction;

  • Person or department authorizing destruction; and

  • Confirmation that no Legal Hold or other preservation requirement applied.

Routine destruction of ordinary administrative records does not necessarily require an individual destruction log unless SOIMT determines otherwise.

14. Policy Exceptions

Exceptions to this Policy may be authorized by the Executive Director, Board of Directors, or legal counsel when circumstances justify a different retention period.

Any exception should be documented and should identify:

  • The records affected;

  • The reason for the exception;

  • The applicable alternative retention period; and

  • The person authorizing the exception.

15. Policy Review

This Policy should be reviewed periodically and whenever there are significant changes to:

  • Applicable laws or regulations;

  • SOIMT's programs or operations;

  • Information systems;

  • Recordkeeping practices;

  • Tax-exempt status or organizational structure; or

  • Litigation, audit, privacy, or regulatory requirements.

The Board of Directors may revise this Policy as necessary.

16. Compliance

Failure to comply with this Policy may result in disciplinary action, termination of access to organizational systems, termination of a volunteer or contractor relationship, or other appropriate action, subject to applicable law and organizational procedures.

Nothing in this Policy authorizes the destruction of records when destruction is prohibited by law or when the records are subject to a Legal Hold.