← All help articles

Deleting documents after you approve them

Deleting documents after you approve them

Collecting insurance certificates and signed agreements is the easy half. Holding them is the half nobody thinks about until someone asks how long you keep other people's paperwork.

By default 1pm keeps every file a contractor sends you until you delete it yourself. That is the right answer for plenty of accounts and the wrong one for others, so Document retention lets you say how long an approved file stays in storage. When the time is up, 1pm deletes the file. Everything you actually rely on stays: the expiry date, who sent it, when, and the fact that you approved it.

This article covers what the setting does, what survives a deletion, and how to decide whether you want it on at all.

Why you might want it

Three reasons come up.

You are holding other people's documents. An insurance certificate carries a policy number and a business address. A right-to-work document carries more. Once you have checked it and recorded what it said, the file itself is doing nothing except sitting there, and a file you no longer hold is a file that cannot be exposed.

Somebody asks. Larger clients and their insurers increasingly ask how long a supplier retains third-party records. "Ninety days after we approve it, then it is purged" is a straight answer. "Forever, we have never deleted one" is not.

Privacy law asks the same thing in general terms. Both Australian and UK/EU rules work on the principle that personal information should not be kept longer than it is needed for. A stated retention period is how you demonstrate you have thought about it.

What is kept and what goes

Only the file goes. The submission stays on the record, and so does everything you would want from it later:

  • The expiry date the contractor entered, so your expiring documents chasing carries on exactly as before.
  • Who sent it, and when, on their request history.
  • The file name and size, so the row still says what the document was.
  • Your approval, with the date you gave it. Or the rejection, with the reason.

What you lose is the ability to open the document and look at it. Where a file link used to sit, the row says the file was deleted and when.

This matters more than it sounds, because it is the difference between two very different claims. You are not deleting the record that you checked a contractor's insurance. You are deleting the copy of their certificate.

Turning it on

Go to Account, then Profile, and find the Document retention card. Choose how long approved files are kept:

  • Keep files until I delete them, the default
  • 7, 30, 90, 180 or 365 days after you approve them
  • 30 days after the document expires

That last one is worth a look before you settle on a fixed number. A certificate that runs until next June is useful for as long as it is valid and useless the day after, so counting from the expiry date rather than from your approval keeps each document for exactly as long as it is worth keeping. A one-year policy approved this week is held for a year and a month. A certificate that expires next month is gone six weeks from now. You do not have to pick a number that suits both.

The shortest window is seven days, and that floor is deliberate. Approve is a single click with no confirmation, so there has to be a window in which a mis-click can be put right. It holds for the expiry-based option too: approve a certificate that lapsed months ago and you still get seven days, rather than losing the file that night.

The rules 1pm applies

Three of these are worth knowing before you switch it on, because each one exists to stop the setting doing something you did not intend.

Approved files are only deleted if an expiry date was captured. An upload request only asks for an expiry date when you tick Require expiry as you create it, or the Expiry box on the request row afterwards. Where no date was collected, the file is the only record of itself, so 1pm keeps it however this setting is configured. If you want retention to apply across the board, turn that box on for the requests that matter. It is worth doing anyway: it is also what drives your expiry chasing.

Rejected files go sooner. A file you rejected is deleted within 30 days, or your own window if that is shorter. Without this the documents you kept longest would be the ones you decided were wrong, which is the opposite of the point. The rejection and your reason stay on the record.

Files nobody has reviewed are never deleted. An upload sitting in your approval queue is evidence somebody sent you something and nobody has looked at it yet. Deleting that would destroy information that was never captured in the first place, so the clock only ever starts at approval or rejection.

It is not retroactive

Each file carries the window it was reviewed under. Changing this setting applies from your next approval onwards.

That means shortening it is safe. Dropping from 365 days to 7 does not sweep away a year of certificates that afternoon: those files keep the 365 days they were approved under, and only files you approve from now on get the new window.

It also means turning it on today does nothing to the files already in your account. Those stay until you delete them by hand.

What the contractor sees

Whoever sent the file sees the same thing you do, on their portal: the submission is still listed, with its expiry date and its approved or rejected status, and a line saying the file was deleted and when.

That line exists because a file quietly becoming unopenable reads as a fault. Told plainly, it reads as a policy, which is what it is.

How long the file really exists

Worth being precise here, because it is the question a compliance officer will actually ask.

When your retention period is up, the file is removed from your account immediately. It is then fully purged from our storage within a further 30 days. That second window is a safety net against a fault at our end, not a feature: there is no way to restore a file from inside 1pm, and nobody at your end can reach it.

So the honest total is your chosen window plus 30 days. If you tell a client you hold their contractors' certificates for 90 days, the accurate version is that you hold them for 90 days and they are gone from our systems within 120.

If a file is deleted and you genuinely need it back inside that window, contact support. Treat it as a last resort rather than an undo: it is a manual recovery, it is not guaranteed, and the seven-day minimum window exists so that ordinary mistakes never need it.

When to leave it off

Off is a legitimate answer, and for some accounts it is the right one.

Leave it off if your own insurer or a client contract requires you to retain contractor documents for a set period, which is common for public liability evidence and can run to several years. Leave it off if you work in a sector with a statutory retention period. The setting caps at 365 days, so if you are required to hold documents for longer than a year, keeping files is the option you want rather than a long window.

If you are unsure, the useful question is not "how long should I keep these" but "who would ask me for one, and when". If the answer is nobody after the certificate expires, retention is doing you a favour. If the answer is an insurer after an incident three years ago, it is not.

Where this fits

Retention is the last step of the document workflow rather than a separate feature. Asking crew for documents collects them, chasing expiring documents keeps them current, a contact's request history is the per-person file, and this decides how long the paperwork itself sticks around after you have signed it off.

If you are running 1pm mainly as a contractor register, using 1pm for onboarding and compliance requests is the fuller walkthrough, and this setting is a sensible thing to configure once you have the collection side working.

Still stuck after reading this? Open a help ticket and we'll answer your specific question.