Privacy Notice

Platinum MGA ERP System — Internal Use Only

This application is an internal tool operated by Platinum MGA for use by authorized staff only. This notice explains how the application uses cookies and handles data in connection with your use of the system.

Cookies We Use

This application uses only strictly necessary cookies. No analytics, advertising, or tracking cookies are used.

CookiePurposeDuration
authjs.session-tokenMaintains your authenticated session8 hours
erp.trusted-deviceRemembers verified devices for 2FA (re-verify every 15 days)90 days
erp.bypass-userAdmin 2FA exemption (set by a database administrator only)Session

Because these cookies are strictly necessary for the application to function, no consent banner is required under the EU ePrivacy Directive or GDPR Article 5(3).

Authentication & Security

Login credentials are verified against the Platinum MGA employee database. Passwords are stored as bcrypt hashes. Two-factor authentication (2FA) codes are one-time-use, expire in 10 minutes, and are discarded immediately after verification. All communication is encrypted in transit (TLS/HTTPS).

Data Retention

This system processes business data solely for the purpose of internal insurance operations. No personal data is sold, shared with third parties for marketing, or used for purposes beyond the operation of the Platinum MGA ERP system.

Questions about this notice or your data? Contact your system administrator.

© 2026 Platinum MGA. Last updated August 2026.