EAHQ

Legal

Privacy Policy

Last updated: 18 August 2026

Who we are

EAHQ (β€œwe”, β€œus”, β€œour”) operates theeahq.com, a curated job board for Executive Assistants, ops-adjacent EAs, and Chiefs of Staff. We are based in the United Kingdom and this policy is written to comply with the UK GDPR and Data Protection Act 2018.

If you have questions about this policy or how we handle your data, contact us at hello@theeahq.com.

What we collect and why

Email addresses. When you sign up for our newsletter, job alerts, or unlock salary data, we collect your email address (and, for job alerts, your preferred role types, location, and other filters you choose) so we can send you the content you asked for. We collect this with your consent at the point of signup.

Job submissions. If you submit a role β€” with an account, either the full details (title, company, location, salary, and so on) or just a URL for us to fill in the rest β€” we store what you provide and link it to your account so we can review it and let you track its status on your submissions page.

Employer claim requests. If you use the β€œis this your role?” flow to edit a listing, we collect your email address to send a one-time verification link and to associate any edits you submit with your account.

Account details. You can create a free account to save roles and submit listings, using Google or LinkedIn sign-in. When you do, we store the name and email address that provider gives us, along with the roles you save and submit. We use this to run your account β€” showing your saved roles, tracking your submissions, and letting you sign back in.

Analytics data. We do not run any visitor analytics or tracking tools (including Google Analytics) β€” no cookies, no individual tracking. The one exception is role view counts: if you claim an organisation's page, your dashboard shows how many times each of your roles has been viewed, in total and over the last 30 days. This is a simple, aggregate, server-side counter tied to the listing β€” it involves no personal data about the candidates viewing it, and no cookies. If we introduce broader site analytics in future, we will update this policy and our cookie notice to describe what's collected and give you control over it.

Newsletter and mailing list

When you sign up for job alerts or create an EAHQ account, your email address may be added to our mailing list for EAHQ Weekly, our newsletter about the EA job market. You can unsubscribe at any time using the link in any email we send.

Candidate profiles and CVs

If you create a candidate profile (at /profile), we store the details you add β€” job title, experience level, industries, location, work preferences, and a short bio β€” along with a CV file if you choose to upload one. You give us this data by choosing to create a profile, so our lawful basis is your consent.

Your profile and CV are private by default. Recruiter search and viewing is a separate, off-by-default toggle on your profile (β€œAllow recruiters to find my profile”) β€” nobody can find or view your profile through search until you switch this on. Recruiters with a claimed EAHQ agency page can search profiles that opt in this way (filtering by level, location, industry, and similar criteria) and view one you've made visible to them. Every time a recruiter views or downloads a CV β€” whether found through search or received via an application β€” we log who accessed it and when, purely for accountability. This log is never shown to you or to other candidates, and it isn't used for anything else.

You can block a specific recruiter agency from finding or viewing your profile at any time from your profile page β€” blocking stops that agency finding you in future searches, but doesn't remove anything from applications you'd already sent them (see below). You can also delete your CV, or your entire candidate profile, whenever you like β€” deleting your account (from your account page) permanently removes your candidate profile and CV file immediately.

Applying for roles

If you apply to a role through EAHQ (rather than via an external link), we send the employer or recruiter behind that specific listing a copy of your profile details and CV as they stood at the moment you applied, along with any covering note you write β€” we tell you this on the application form before you submit. Recruiters can then update your application's status (which emails you), and see any other roles of theirs you've applied to. If a role is placed through a recruitment agency, the agency sees applications the same way an employer would for their own roles.

You can withdraw an in-site application at any time from /my-applications β€” this notifies the employer/recruiter and marks it withdrawn, but (as with other business records) we keep the fact that you applied and withdrew rather than deleting it outright. You can also track roles you applied to outside EAHQ by self-reporting them on the same page β€” those entries are private to you and are never shared with the employer or recruiter.

We keep application data for as long as it's useful for hiring purposes β€” typically no more than 12 months after the role closes β€” after which we automatically anonymise it: the link to your candidate profile, your CV copy, and your covering note are all removed, while the employer/recruiter keeps a record that an (anonymous) application was received, for their own hiring records. Deleting your account anonymises your in-site applications the same way immediately, rather than waiting out that window. Roles you self-reported applying to elsewhere are deleted outright when you delete your account, since no employer or recruiter ever had visibility into them.

Lawful basis for processing

We process your email address and related preferences on the basis of your consent, which you give when you sign up and can withdraw at any time by unsubscribing. Where we process data to respond to a submission or claim request you've made, our basis is legitimate interest in operating the job board and keeping listings accurate.

Who we share data with

We use a small number of third-party service providers (β€œprocessors”) to run EAHQ. Each only receives the data it needs to provide its service to us:

  • Supabase β€” our database provider, which stores job listings, submissions, subscriber data, and account/saved-role data.
  • Vercel β€” our hosting provider, which serves the site and processes web traffic.
  • Beehiiv β€” our newsletter platform, which manages newsletter subscriber lists and sends our weekly digest.
  • Resend β€” our transactional email provider, used to send one-time verification links for the employer claim flow.
  • Stripe β€” our payments processor, used for organisation page subscriptions and featured-role placements. We never see or store your card details. Stripe operates as the merchant of record for these payments under its Managed Payments service, meaning it handles tax (VAT/sales tax) collection and remittance directly β€” see Stripe's privacy policy for how they handle payment data.
  • Google and LinkedIn β€” if you choose to sign in with either, they share your name and email address with us to create your account. We don't request or receive anything beyond that.
  • Google Places API β€” job listing locations are resolved through Google's Places API into a city, region, and coordinates, so roles can be searched and filtered by location. This applies to where a role is based, not to any personal data about you β€” see Google's privacy policy for how they handle it.

We do not sell your personal data to anyone, and we do not share it with third parties for their own marketing purposes.

How long we keep your data

We keep newsletter and job alert subscriber data for as long as your subscription is active, and delete it within 30 days of you unsubscribing. Job submissions and claim requests are kept for as long as needed to process them and for a reasonable period afterwards for record-keeping, typically no more than 12 months.

Account data β€” your profile, saved roles, and submission history β€” is kept for as long as your account is active. If you delete your account from your account page, we immediately delete your profile and saved roles, and remove your name and email from any roles you've submitted. The roles themselves stay live, since removing them would affect other people relying on that listing. If you have a candidate profile, deleting your account also immediately deletes it and your CV file.

Your rights

Under UK GDPR, you have the right to access the personal data we hold about you, ask us to correct or delete it, object to or restrict certain processing, and request a copy of your data in a portable format. You can unsubscribe from any email list at any time using the link in the email, or via your preferences page (the link sent in your alert emails). If you have an account, you can edit your details or delete your account at any time from your account page.

To exercise any of these rights, email us at hello@theeahq.com. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we haven't handled your data properly.

Changes to this policy

We may update this policy from time to time, for example if we add new features or change service providers. We'll update the β€œlast updated” date at the top of this page when we do.