Cookie notice
Only what the service needs.
MSA currently uses necessary security and application storage—not advertising cookies, analytics pixels, or cross-site behavioural tracking.
Version cookies-2026-08-22 · Effective 22 August 2026No advertising, social-media tracking, or third-party analytics cookie is intentionally deployed. If that changes, this notice and the consent mechanism must be updated before non-essential technology is activated.
1. Necessary session cookie
| Name | Purpose | Duration |
|---|---|---|
__Host-maritime_session | Keeps a verified user signed in, applies account permissions, and protects the portal session. It is host-only, Secure, HttpOnly, SameSite Strict, and unavailable to client-side scripts. | Up to 12 hours, or earlier logout/revocation |
Local development may use the name maritime_session without weakening the production cookie's host-only protections.
2. PWA and cache storage
If a user installs the MSA progressive web app or visits supported pages, the browser may store a small offline shell, the manifest, logo, public images, fonts, CSS, JavaScript, and an offline page. The service worker does not intentionally cache private portal pages, API responses, messages, or uploaded documents. A user can clear this storage through browser or device site settings.
3. Server security records
Request logs and protected hashes derived from connection and device information are server records, not browser cookies. They are used for rate limiting, account protection, diagnostics, and abuse prevention and are handled under the Privacy Notice.
4. Why no cookie banner appears
The present technology is limited to what is necessary to deliver security, account access, and an explicitly requested installable application. MSA does not rely on a banner to make necessary storage lawful. If optional analytics, advertising, personalisation, or embedded third-party media is introduced, it must remain disabled until any consent required by applicable law is obtained.
5. Browser choices
A user can block or delete site data in browser settings. Blocking the session cookie will prevent portal sign-in. Clearing PWA storage may remove offline assets but does not delete the server account or portal records; those require the account or privacy request process.
Questions or rights requests
Contact MSA through the protected enquiry route.
Use the contact form for legal, privacy, cancellation, or complaint matters. Do not include passport numbers, medical information, or document copies in the public form.
Contact the agency