1. Purpose
This schedule sets out the Group's approach to retaining, preserving, protecting and disposing of records connected with Turks and Caicos Islands operations.
The purpose is to support lawful trading, corporate compliance, employment management, tax and customs compliance, customer service, safety management, financial control, licence compliance, legal defence, insurance claims and orderly disposal of records when they are no longer needed.
This schedule is not intended to require unnecessary storage of every document. It sets practical default periods that may be shortened or extended where law, regulator instruction, contract, insurance, litigation risk, data minimisation or business need requires a different period.
2. Scope
This schedule applies to Murzo Group Ltd and all subsidiaries, controlled entities, divisions, brands, branches, projects, premises, platforms, accounts and operations conducting business in or from the Turks and Caicos Islands.
It applies to paper records, electronic records, databases, emails, messages, photographs, CCTV, logs, cloud files, accounting records, HR records, licence records, customer records, safety records, supplier records, payment records, product records and third-party records held for or on behalf of the Group.
3. TCI Legal and Regulatory Context
TCI records may be relevant to the Financial Services Commission, Companies Registry, Revenue Department, Environmental Health Department, Labour and Employment Services, customs authorities, immigration authorities, courts, insurers, law enforcement, sector regulators, landlords, banks, payment providers and contractual counterparties.
The FSC Registry administers company, partnership, business name, trademark and patent functions and maintains public information filed under relevant ordinances. Business licence renewal may require directors, members or shareholders, beneficial ownership and good standing evidence where applicable.
Some regulated or supervised activities, including AML/CFT-sensitive activity, may have specific record-keeping duties. Civil limitation periods, regulator investigations, employment disputes, tax reviews, product issues, customer claims, insurance claims and serious incidents may require records to be preserved beyond ordinary business use.
4. Retention Principles
- Retain records for a clear legal, regulatory, contractual, operational, safety, financial or evidential reason
- Do not retain personal data or confidential material longer than reasonably necessary without justification
- Apply the longest applicable requirement where several duties overlap
- Preserve records immediately when a legal hold applies
- Keep sensitive records access-controlled and protected from unauthorised alteration or deletion
- Dispose of records securely when retention has expired and no legal hold applies
5. Legal Hold Overrides Normal Disposal
A legal hold suspends routine deletion, destruction, overwriting, anonymisation or alteration of relevant records where litigation, a claim, an accident, a regulator inquiry, a law enforcement matter, an audit, an insurance claim, an employment dispute, a customer dispute, a safety incident, a product issue, a tax or customs review, an AML or sanctions concern, a data breach, a property dispute, a cultural property claim or another serious matter is reasonably anticipated or active.
Once a legal hold is issued, affected people must preserve relevant records until the hold is released by an authorised person. Preservation is not an admission of liability.
6. Default Retention Schedule
The following table gives default retention periods for TCI records. A shorter or longer period may apply where the law, regulator, court, insurer, contract, platform, tax authority, customs authority, employment matter or legal hold requires it.
| Record Type | Examples | Default Retention | Notes |
|---|---|---|---|
| Corporate and entity records | Incorporation documents, articles, registers, directors, members, shareholders, beneficial ownership, registered agent details, good standing, corporate filings, board approvals and resolutions | Life of entity plus 7 years after dissolution, withdrawal, sale or cessation of TCI activity | Core constitutional and ownership records may be kept longer where needed to prove title, authority, beneficial ownership, tax position or historic control. |
| Business licences and permits | Licence applications, renewals, clearances, SIGTAS registration, sector approvals, premises particulars, fee evidence, regulator correspondence, inspections and change notices | Current licence period plus 7 years after expiry, cancellation, refusal, suspension or cessation of the activity | Keep longer where a licence condition, investigation, appeal, insurer requirement, property matter or regulator request applies. |
| Tax, revenue and customs records | Invoices, receipts, tax returns, remittance evidence, customs declarations, import/export documents, duty payments, concessions, exemptions, broker instructions and authority correspondence | 7 years from the relevant tax period, customs entry, transaction or filing | Retain longer for audits, unpaid duties, disputed values, concessions, high-value goods, cultural objects, sanctions, fraud concerns or legal hold. |
| Financial and accounting records | Ledgers, bank statements, reconciliations, expenses, purchasing approvals, cash records, payment reports, refunds, chargebacks, supplier invoices, audit files and insurance claim evidence | 7 years from financial year end or transaction closure | Asset, property, fraud, AML, insurance and litigation-related records may require longer retention. |
| Employment and immigration records | Contracts, offer letters, work permits, right-to-work evidence, payroll, wage records, leave, benefits, training, disciplinary, grievance, performance, sickness, termination and deductions | Employment plus 7 years after termination or end of TCI assignment | Serious disputes, work-permit issues, injury claims, pension, tax, housing or immigration matters may justify longer retention. Unsuccessful recruitment records should normally be kept only as long as needed for hiring, dispute and compliance purposes. |
| Health, safety and wellbeing records | Risk assessments, incident reports, accident evidence, first aid records, training, PPE, inspections, emergency drills, maintenance, exposure records and regulator correspondence | 7 years from creation or incident closure | Serious injury, fatality, hazardous exposure, occupational illness, product safety, environmental release or legal claim records may require long-term retention. |
| Customer, consumer and marketplace records | Orders, bookings, customer contracts, complaints, refunds, support tickets, delivery evidence, account notes, marketing consent, marketplace reports and dispute correspondence | 7 years from transaction closure, complaint closure or account closure | Marketing records should be minimised when consent is withdrawn, subject to suppression lists or evidence needed to prove compliance. |
| Property, facilities and asset records | Leases, licences to occupy, title documents, acquisition files, inspections, maintenance, service records, asset registers, insurance, photographs, landlord correspondence and disposal evidence | Life of asset, lease or occupancy plus 7 years | Title, provenance, warranty, planning, contamination, major works, structural, insurance and dispute records may be retained longer. |
| Food, product, farming and biosecurity records | Batch records, traceability, supplier evidence, product testing, HACCP, allergen controls, cleaning, pest control, recall files, animal or insect movement, quarantine and disposal | Product life plus 7 years, or 7 years from activity closure where no product life is applicable | Live insect, animal, feed, food safety, recall, environmental or injury matters may require extended retention under legal hold or sector control. |
| High-value goods, cultural property and provenance records | Ownership evidence, provenance, authenticity, valuation, customs documents, export licences, import permits, sanctions checks, source of funds and repatriation or claim correspondence | While held or marketed plus 20 years after sale, disposal or withdrawal | Retain longer where title, cultural property, human remains, sacred objects, sanctions, AML, fraud or repatriation claims may arise. |
| Security, CCTV and access records | CCTV, visitor logs, access-control logs, alarm records, key records, security incident reports, body-worn camera footage and investigation evidence | Short operational period unless linked to an incident; incident material for 7 years after closure | CCTV should not be kept longer than necessary unless needed for security, safety, employment, insurance, law enforcement or legal hold. |
| Legal, claims and disputes | Legal advice, claim correspondence, settlement papers, court documents, regulator notices, investigation files, insurer files and legal hold notices | Until matter closure plus 7 years, unless legal advice requires longer | Privileged records must be protected. Do not dispose of any record subject to an active hold. |
7. Corporate Records
Corporate records should show the entity, ownership, authority, registered agent, directors, members, beneficial ownership, corporate status, filings, approvals and lawful authority for TCI activity.
Corporate records that prove legal existence, ownership, title, beneficial ownership, board authority, registered agent authority or material transactions should be treated as high-value records and protected from unauthorised alteration.
8. Employment Records
Employment records should support lawful recruitment, work permits, contracts, wages, hours, holidays, accommodation duties where applicable, disciplinary process, grievance handling, termination, health and safety, training and payroll obligations.
Access to employment records must be limited to people with a genuine business, legal, payroll, immigration, safety or management need.
9. Tax, Customs and Financial Records
Tax, customs and financial records must be sufficient to explain transactions, payment flows, imports, exports, duties, licence fees, taxes, remittances, refunds, expenses, cash movements and supplier payments relevant to TCI activity.
Records should allow the Group to respond to Revenue Department, customs, bank, insurer, auditor, platform, regulator or legal requests without creating unnecessary duplicate files.
10. Customer and Personal Information
Customer records should be kept only for as long as needed for the transaction, service, complaint, warranty, product safety, marketplace, tax, legal, insurance, security or customer relationship purpose.
Personal information must be protected against unauthorised access, disclosure, alteration, loss, misuse and excessive retention. UK data protection duties and other cross-border privacy duties may apply where data is processed by or for a UK-based Group entity.
11. Safety and Incident Records
Safety records may include accident reports, first aid records, risk assessments, training evidence, inspection records, maintenance logs, emergency drill evidence, photos, witness notes, regulator correspondence, insurer correspondence and corrective action evidence.
Serious incidents should be preserved under legal hold where litigation, regulator action, employment dispute, insurance claim or public safety concern is reasonably possible.
12. Licence and Regulator Records
Licence records should show what activity was authorised, which entity was authorised, which premises or online channel was covered, what conditions applied, when renewal or change notification was required and whether any regulator correspondence remains unresolved.
No person may alter, backdate, delete or selectively remove licence records to disguise unlicensed activity, missed renewal, false ownership, incorrect premises, unauthorised trading or regulator concern.
13. Legal Hold Triggers
A legal hold may be triggered by:
- Threatened or actual litigation, arbitration, mediation or settlement discussions
- Regulator, court, customs, tax, police, immigration, employment, health and safety or Environmental Health contact
- Serious accident, death, injury, illness, exposure, near miss, product issue, recall, environmental release or biosecurity incident
- Employment grievance, disciplinary matter, termination dispute, whistleblowing report or harassment complaint
- Fraud, theft, payment compromise, AML, sanctions, corruption, source-of-funds or high-value goods concern
- Customer complaint, marketplace dispute, chargeback, warranty claim, product liability allegation or public allegation
- Property, lease, title, planning, landlord, cultural property, provenance or repatriation claim
- Insurance claim, broker request, insurer instruction or loss adjuster involvement
14. Legal Hold Duties
When a legal hold applies, affected people must preserve relevant paper records, electronic records, emails, messages, attachments, photographs, CCTV, logs, device data, cloud folders, databases, notebooks, drafts, calendars, call notes and third-party records within their control.
Normal deletion, overwriting, shredding, recycling, anonymisation, auto-delete settings, device wiping, account closure and storage clean-up must be paused for relevant records until the hold is released.
A person who is unsure whether a record is relevant must preserve it and escalate rather than delete it.
15. Electronic Systems and Backups
Electronic records should be stored in approved systems where practicable. Access should be role-based, protected by appropriate security controls and removed when a person no longer needs access.
Backups are primarily for business continuity and disaster recovery. A legal hold may require steps to prevent relevant data being overwritten where the data is not otherwise preserved in an accessible system.
16. Third Parties and Platforms
Suppliers, contractors, registered agents, company managers, customs brokers, payroll providers, accountants, banks, payment providers, marketplaces, fulfilment providers, landlords and technology providers may hold records relevant to TCI activity.
Contracts and instructions should require third parties to preserve, return, provide or securely delete records where legally and contractually appropriate. A third party must not destroy records after receiving a preservation instruction from the Group.
17. Secure Disposal
Records may be disposed of only when the retention period has expired, there is no legal hold, there is no regulator or insurer reason to keep them, and disposal is consistent with data protection, confidentiality, tax, employment, safety, product and contractual duties.
Secure disposal may include shredding, certified destruction, secure deletion, access removal, anonymisation, de-identification, return to owner or controlled archiving. Disposal must not be used to hide wrongdoing, avoid disclosure, defeat a claim or mislead an authority.
18. Access, Confidentiality and Privilege
Records containing personal data, financial data, medical information, employee information, customer information, security information, legal advice, trade secrets, provenance evidence, source-of-funds material or regulator correspondence must be access-controlled.
Legal advice and privileged material must not be circulated unnecessarily. Privilege may be lost if legal advice is shared carelessly.
19. Accountability
Failure to comply with this schedule may result in access restriction, retraining, disciplinary action, contract remedies, insurer notification, regulator notification, law enforcement referral or other lawful action.
Deliberate destruction, concealment, alteration, backdating, selective deletion or misleading creation of records may be treated as serious misconduct or contractual breach.
20. Relationship With Other Policies
This schedule should be read with the TCI Legal and Regulatory Compliance Policy, TCI Business Licensing and Corporate Compliance Procedure, TCI Employment and Workplace Policy, TCI Health, Safety and Wellbeing Policy, TCI Financial Controls, Fraud and Cash-Handling Policy, TCI Hurricane, Disaster and Business Continuity Policy, Records Retention and Legal Hold Policy, Data Protection Policy, Cybersecurity and Data Breach Policy, Tax Governance and Compliance Policy, Customs Import/Export Policy, Fraud Prevention and Economic Crime Policy, High-Value Goods, Anti-Money Laundering and Source of Funds Policy, Food Safety policies, Biosecurity policies, Cultural Property and Provenance Policy, and Insurance and Liability Disclosure Statement.