Privacy Policy
Last updated: 26 July 2026
Operator: Erika Labs
Product: Eosord & EOSlink (eosord.com)
Introduction
- Eosord and EOSlink are operated by Erika Labs from Scotland, United Kingdom. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our website and platform.
- Eosord is recruitment software for hiring teams. EOSlink is a candidate profile product that is part of the same platform.
- We aim to handle personal data responsibly and in line with applicable requirements in the jurisdictions where our users operate, including the United States, Canada, the United Kingdom, the European Union, Australia, New Zealand, and Singapore, as well as other countries where the service is accessed.
- We respect UK GDPR, EU GDPR, the California Privacy Rights Act (CPRA) where applicable, and other data protection laws that apply to our processing.
Who this applies to
- Recruiters and hiring teams who create an Eosord account and use hiring features.
- Candidates who create an EOSlink account, publish a profile, or use profile visibility and open-to-work settings.
- Job applicants who submit applications through public apply forms (with or without an account).
- Individuals who use tokenized scheduling links, client review links, or organisation invite links.
- Visitors to our public website, careers pages, and public @handle profile pages.
Personal data we process
- Recruiters: name, email, phone, location, role, account credentials, organisation membership, jobs, applicant pipeline data, notes, outbound email records, reports usage, and support ticket content.
- Organisation workspaces: organisation name, slug, logo, careers page content, member list, invites, and role assignments.
- Calendar integrations (optional): scheduling email, connected provider account email, encrypted OAuth tokens, connection metadata, and calendar event details needed for interview scheduling.
- EOSlink profiles: display name, @handle, headline, location, about text, skills, links, experience, education, custom sections, theme settings, avatar image, publish status, open-to-work status, and email/phone visibility preferences.
- Find people and matching: where a profile is published and open to work, we may process profile content and embeddings to power recruiter search and relevance scoring. Contact fields are shown only according to visibility settings.
- Job applicants: name, email, phone, location, PDF resume, custom application answers, application source, status, and related pipeline data visible to the posting organisation.
- Scheduling and review links: booking choices, token metadata, and—for client review—email verification of the intended recipient before access is granted.
- Technical data: essential server logs, security records, and similar data needed to operate and protect the service.
- We do not sell personal data. We do not share personal data with third parties for their own advertising or marketing purposes.
How we use personal data
- Provide, operate, maintain, and improve Eosord and EOSlink.
- Authenticate users, manage accounts, and enforce access controls.
- Publish jobs, careers pages, and EOSlink public profiles according to your settings.
- Collect and route job applications to the recruiting organisation posting the role.
- Support recruiter workflows including shortlisting, pipeline management, email, reports, Find people search, and AI-assisted features where enabled.
- Schedule, reschedule, or cancel interviews when calendar integrations are connected.
- Enable client review of shortlisted candidates through tokenized links.
- Send service-related communications such as acknowledgements, invitations, and account messages.
- Respond to support and privacy requests.
- Maintain security, prevent misuse, and comply with legal obligations.
- Applicant data is processed for the recruiting organisation's hiring process and is not shared with unrelated third parties for marketing.
Legal basis (UK / EU GDPR)
- Contract — to provide the service you request (for example account features, applications, or scheduling).
- Legitimate interests — to operate, secure, and improve the platform, prevent fraud, and support recruitment workflows (balanced against your rights).
- Consent — where required (for example certain optional settings or communications).
- Legal obligation — where the law requires us to retain or disclose data.
- For job applications, candidates provide data voluntarily when applying; recruiting organisations are responsible for their hiring process and lawful basis for reviewing applicants.
- For EOSlink profiles, you control publish, open-to-work, and visibility settings within the product.
Data security
- We take data security seriously and follow industry best practices to protect personal data.
- We use appropriate technical and organisational measures, including access controls, encryption in transit (HTTPS), secure cloud infrastructure, and secure handling of sensitive credentials such as calendar OAuth tokens.
- Access to production systems and personal data is limited to authorised personnel and systems that need it to operate the service.
- We do not deliberately sell personal data and do not permit service providers to use personal data for their own unrelated marketing.
- No online service can guarantee absolute security. Please use a strong password and notify us if you suspect unauthorised access to your account.
Service providers
- We use trusted infrastructure and service providers who process data on our instructions under contractual safeguards.
- Categories may include hosting, authentication, email delivery, storage, and AI processing limited to relevant job, application, and profile context.
- When you connect a calendar, Google or Microsoft processes sign-in and calendar API requests according to their own privacy policies.
- Providers may process data in the UK, EU, US, or other countries. We use appropriate safeguards for international transfers where required by law.
Calendar integrations (Google Calendar and Microsoft Outlook)
- Optional feature: recruiters may connect Google Calendar or Microsoft Outlook/365 on the Integrations page. Connection is never required to use other parts of Eosord.
- What we access: with your permission, Eosord reads event times on the calendar you connect to determine when you are busy or free for interview scheduling, and creates calendar events when an interview is booked (including title, time, attendees, location or online meeting details, and reminders). We access only what is needed for scheduling—not your email inbox, contacts, or unrelated files.
- Google scopes: openid, email, profile, and Google Calendar events (https://www.googleapis.com/auth/calendar.events). Microsoft permissions: sign-in (openid, email, profile) and calendar read/write via Microsoft Graph (e.g. Calendars.ReadWrite) when you connect Microsoft.
- What we store: your chosen scheduling email, the email of the Google or Microsoft account you signed in with, encrypted OAuth access and refresh tokens, token expiry, connection timestamp, and granted scopes. We do not store a full copy of your calendar long term.
- How we use calendar data: solely to provide interview scheduling inside Eosord for your organisation. We do not use Google or Microsoft user data for advertising, profiling, creditworthiness, or selling to data brokers. We do not use calendar data to train general-purpose AI models.
- Google API Limited Use: Eosord's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Sharing: calendar data is not sold. It is shared only with service infrastructure that hosts Eosord (under contract), with Google or Microsoft when making API calls you authorise, and with meeting attendees you include when an event is created.
- Retention: calendar connection data is kept while your integration is active. When you disconnect in Eosord, we revoke tokens where supported, mark the connection inactive, and delete or anonymise stored tokens and connection metadata within a reasonable period unless we must retain minimal records for security, fraud prevention, or legal compliance.
- Revoking access: you may disconnect at any time in Eosord under Integrations. You may also revoke Eosord in your Google Account (Security → Third-party access) or Microsoft account (My Apps / Enterprise applications / connected apps).
AI features
- Where AI features are enabled (for example job description generation, match scoring, AI Hub, or per-applicant Q&A), relevant job, application, resume, and profile content may be processed to generate results.
- AI outputs support recruiter workflows; recruiters remain responsible for final hiring decisions.
- We do not use personal data processed through AI features for unrelated advertising or for selling data to third parties.
Cookies and similar technologies
- We use essential cookies and similar technologies needed to keep the service secure and functioning (for example authentication and session management).
- Our cookie notice on the marketing site describes how we use cookies. We do not use third-party advertising trackers on our website.
- If we introduce optional analytics in future, we will update this policy and, where required, seek consent.
Data retention
- We keep personal data only as long as needed to provide the service, meet legal requirements, and resolve disputes.
- Recruiters and organisations may delete or archive jobs and related data subject to platform capabilities.
- EOSlink users may unpublish or delete profile content through the editor where available.
- Calendar OAuth tokens and connection records are removed or deactivated when you disconnect an integration, as described above.
- Closed organisation workspaces may retain data until restored or deleted in accordance with product controls and legal requirements.
International transfers
- Erika Labs is based in Scotland, United Kingdom. Personal data may be processed in the UK and in other countries where our service providers operate.
- If personal data is transferred outside the UK or EEA, we use appropriate safeguards (such as standard contractual clauses, adequacy decisions, or equivalent mechanisms) where required by law.
- We design our practices with international users in mind, including users in the United States, Canada, the European Union, Australia, New Zealand, and Singapore.
Your rights
- Depending on where you live, you may have the right to access, correct, delete, restrict, or object to certain processing of your personal data.
- You may have the right to data portability where applicable, and to withdraw consent where processing is consent-based.
- UK and EU users may complain to a supervisory authority (for example the Information Commissioner's Office in the UK).
- California residents (CPRA): you may have rights to know, delete, and correct personal information, and to opt out of sale or sharing. We do not sell or share personal data for cross-context behavioural advertising.
- Users in other jurisdictions may have similar rights under local law. If mandatory law in your country gives you rights that cannot be waived, those rights apply.
- To exercise your rights, contact us using the details below. We may need to verify your identity.
Children
- Eosord and EOSlink are not intended for individuals under 16. We do not knowingly collect personal data from children.
Changes to this policy
- We may update this Privacy Policy from time to time. The last updated date will change when we do.
- Continued use of the service after changes take effect means you accept the updated policy, unless applicable law requires a different process.
Contact
- Email: contact@erikalabs.com (subject line: Eosord Privacy Request).
- Erika Labs — operator of Eosord and EOSlink, based in Scotland, United Kingdom.