Privacy notice
Your records remain your story.
This notice explains how MSA handles account, identity, career, document, communication, and technical information across the website and secure portal.
Version privacy-2026-08-23 · Effective 23 August 2026MSA uses information to answer enquiries, operate secure accounts, deliver requested consultancy support, protect the platform, and—only when authorised—coordinate with a selected school, employer, professional partner, or competent authority. MSA does not sell personal information and does not use uploaded documents for advertising.
1. Scope and controller
This notice applies to maritimesupportagency.com, portal.maritimesupportagency.com, MSA communications, and information processed while assessing or delivering an MSA service. Maritime Support Agency (MSA), the independent consultancy operating the platform, determines the purposes and means of this platform processing and acts as controller where data-protection law uses that term. The responsible contracting provider and service address are identified in the applicable Service Order or account correspondence. Privacy questions and rights requests may be submitted through the contact route below.
2. Information collected
- Enquiry data: name, email, optional phone number, requested service, message, and submission time.
- Account and security data: legal name, email, password hash, verification status, login protection, session records, security-event history, and multi-factor authentication status. MSA does not store a readable account password.
- Profile and career data: nationality, residence, date and place of birth, contact details, occupation, rank, experience, employer, availability, role preferences, asset type, and professional biography.
- Maritime records: sea-service entries, vessel and company information, certificates, endorsements, discharge-book records, educational records, CVs, and related application evidence.
- Identity and document data: passport or identity images, photographs, document numbers, issuer, country, issue and expiry dates, file metadata, cryptographic checksums, malware-scan status, storage-encoding records, and internal review notes. Career and identity evidence may be compressed in private storage, but MSA restores and checks the exact uploaded bytes before every authorised download; it does not reduce the visual quality or alter the content of those records.
- Potentially sensitive data: medical-fitness certificates and limited health information where strictly necessary for a requested service. Clients must not upload unrelated medical history, criminal-offence information, biometric templates, or another person's documents without written authority.
- Service data: requests, messages, opportunity preferences, sharing instructions, complaints, quotes, Service Orders, fees, and transaction references. Payment-card details should be handled by the selected payment provider and not entered in MSA messages.
- Professional-network data: the separately controlled network headline, location, biography, career signals, directory and field-visibility choices, group memberships, posts and attached photos, image-accessibility descriptions, comments, reactions, saved posts, connection requests, accepted connections, blocks, private connection messages, read state, moderation decisions, and safety reports. Attached photos are malware-scanned, automatically oriented, resized where necessary, re-encoded to a web-efficient image format, and stripped of embedded metadata such as camera or location fields before protected storage. They are delivered only after account and audience checks. This processing can change the photo file and reduce its resolution; members should retain their own original. A safety report preserves a limited evidence snapshot so deleting the reported content does not defeat an active investigation.
- Technical data: IP-derived security values, user-agent security values, necessary cookies, request timestamps, and application logs.
3. Sources
Information normally comes from the client. It may also come from an authorised representative, school, employer, shipowner, recruiter, training provider, issuing administration, certificate register, vessel or company record, or professional partner involved in a client-directed case. When information comes from another source, MSA will provide any notice required by applicable law unless an exception applies.
4. Purposes and legal bases
| Purpose | Typical basis |
|---|---|
| Answer an enquiry and assess a requested service | Steps requested before a contract; legitimate service administration |
| Create and secure an account | Contract performance; security and fraud-prevention interests |
| Prepare, organise, review, and track a client's case | Contract performance and the client's documented instructions |
| Operate member profiles, groups, connections and connection-only messages | Contract performance; the member's voluntary network choices; legitimate professional-community administration |
| Moderate content, investigate reports, prevent scams and preserve proportionate evidence | Legitimate safety, fraud-prevention and legal-claims interests; legal obligations where applicable |
| Share a selected record with a named third party | Contract performance, explicit client instruction, and—where required—separate consent |
| Process medical-fitness or other specially protected data | A permitted special-category condition, normally explicit and specific consent where appropriate |
| Meet accounting, complaint, regulatory, or court duties | Legal obligation or establishment, exercise, or defence of legal claims |
| Protect users, systems, and service integrity | Legitimate security interests and legal obligations |
Accepting Terms and acknowledging this notice are contractual records; they are not treated as consent for every processing activity. Where MSA relies on consent, it will request a separate, specific choice and explain how to withdraw it.
5. Data minimisation and client instructions
MSA will request only information reasonably connected to a stated service. The public enquiry form must never be used for passports, certificates, medical information, document numbers, or payment data. Portal upload authorisation allows MSA staff to store and review documents for the client's MSA case; it does not authorise external sharing. External sharing requires a separate, recorded instruction identifying the recipient or recipient category and purpose.
6. Special-category and medical data
A medical-fitness certificate may reveal health information. MSA will process it only where necessary for the client's requested pathway and where a lawful special-category condition applies. MSA is not a healthcare provider and does not make medical-fitness decisions. Clients should provide the minimum certificate or fitness evidence requested, not full clinical records, unless a competent recipient lawfully requires them.
7. Recipients
Access is limited to authorised MSA personnel and service providers who need the information. Depending on a client's instruction and case, recipients may include a selected maritime school, training provider, employer, shipowner, properly authorised recruiter, medical provider, issuing or recognising administration, embassy or travel provider, technology/hosting provider, payment provider, professional adviser, insurer, auditor, or lawful authority. MSA will not represent a recipient as approved, licensed, or official unless that status has been checked against a reliable source.
8. International transfers
Maritime careers are international. A requested service may require a transfer to a recipient in another country. Before a non-routine transfer, MSA will identify the destination and purpose and use a lawful transfer mechanism where required. A client may decline an optional transfer, although MSA may then be unable to perform the affected service. Internet hosting or support providers may also process information in their documented service locations under contractual safeguards.
9. Retention
| Record | Standard target |
|---|---|
| Unconverted public enquiries | Up to 12 months after last contact |
| Active account and service file | While active and normally up to 24 months after closure |
| Client-uploaded document | Until client deletion, case completion plus 90 days, or a justified legal hold—whichever valid rule applies |
| Network profile, posts, comments and messages | While active; member deletion where available; otherwise account closure plus up to 24 months |
| Safety report and limited evidence snapshot | Investigation closure plus the complaint, fraud or legal-claims period reasonably required, normally up to 7 years |
| Security and audit events | Normally up to 24 months |
| Contracts, invoices, and legal acceptance records | Up to 7 years or the period required by applicable tax/claims law |
| Complaints and dispute records | Up to 7 years after closure where reasonably required |
| Encrypted operational backups | Rolling 14-day cycle unless preserved for a documented incident or legal hold |
These are default operational targets. A shorter or longer period may apply where law, a competent authority, an active dispute, fraud prevention, or a documented Service Order requires it. MSA should record the reason for an exception.
10. Deletion and account closure
Clients can delete individual uploaded documents, sea-service entries, network posts, comments, and messages through the portal, and may remove connections or reverse their own blocks. A safety report and its limited evidence snapshot may remain restricted from ordinary members where proportionate investigation, fraud-prevention, complaint, or legal-claims needs justify retention. An account-access, correction, export, restriction, objection, or closure request may be submitted through the contact route. Deletion removes live files through the platform workflow; residual encrypted backup copies expire through the backup cycle unless a legal hold applies. MSA may retain minimal evidence of the request, contract, payment, legal acceptance, or safety investigation where lawfully necessary.
11. Security
MSA uses separate public and portal origins, encrypted HTTPS transport, server-side access controls, private file storage, file-type and content checks, malware scanning, password hashing, session protections, role-based staff access, multi-factor authentication for staff, audit records, encrypted backups, and restricted infrastructure access. No internet service can promise absolute security. Clients must protect their credentials, use a trusted device, sign out on shared devices, and report suspicious activity promptly.
12. Rights
Depending on applicable law, a person may have rights to be informed, access data, correct it, receive a portable copy, request deletion or restriction, object to certain processing, withdraw consent without affecting earlier lawful processing, and complain to a competent supervisory authority. MSA may verify identity before acting and may refuse or limit a request only where law permits. MSA does not use portal data for solely automated decisions producing legal or similarly significant effects.
13. Children
The self-service portal is intended for people aged 18 or over. A person under 18 must not create an independent account or upload identity or maritime documents. A parent or lawful guardian should contact MSA so that age-appropriate notices, authority, and safeguards can be arranged before information is collected.
14. Incidents and complaints
MSA maintains an incident process to contain, assess, document, and remediate suspected personal-data breaches. Where applicable law requires notification to affected people or a supervisory authority, MSA will notify within the required timeframe. Privacy complaints follow the Complaints Policy and do not remove a person's right to approach a competent authority.
15. Changes
Material changes will receive a new version and effective date. Where a change materially affects an active account or document-processing instruction, MSA may require a new acknowledgement or authorisation before further processing. Earlier versions and acceptance evidence are retained where reasonably required to establish which terms applied.
Questions or rights requests
Contact MSA through the protected enquiry route.
Use the contact form for legal, privacy, cancellation, or complaint matters. Do not include passport numbers, medical information, or document copies in the public form.
Contact the agency