arbooONE consists of two areas. The backend allows responsible persons from our customers the management of bookable resources within their locations. They can easily upload floor plans, place bookable resources on them and define permissions for booking the resources. The second part to our offer is a Microsoft Teams App, which allows users to locate and book free resources, to manage bookings and to search for colleagues to see where they have reserved resources for themselves.
Company headquarter location
Germany
App info page
What is the hosting environment or service model used to run your app?
IsvHosted
Questions
Questions or updates to any of the information you see here? Contact us!
How the app handles data
This information has been provided by arboo GmbH about how this app collects and stores organizational data and the control that your organization will have over the data the app collects.
Information
Response
Does the app or underlying infrastructure process any data relating to a Microsoft customer or their device?
Yes
What data is processed by your app?
User Principal Name, Display Name, booking times
Does the app support TLS 1.1 or higher?
Yes
Does the app or underlying infrastructure store any Microsoft customer data?
Yes
What data is stored in your databases?
TenantId, Timezone of User, Locale of User
If underlying infastructure processes or stores Microsoft customer data, where is this data geographically stored?
Netherlands (the), Ireland
Do you have an established data rentention and disposal process?
Yes
How long is data retained after account termination?
Less than 60days
Do you have an established data access management process?
No
Do you transfer customer data or customer content to third parties or sub-processors?
No
Questions
Questions or updates to any of the information you see here? Contact us!
Does the app perform automated decision making, including profiling that could have a legal effect or similar impact?
No
Does the app process customer data for a secondary purpose not described in the privacy notice (i.e. marketing, analytics)?
No
Do you process special categories of sensitive data (i.e. racial or ethnic origin, political opinion, religious or philosophical beliefs, genetic or biometric data, health data) or categories of data subject to breach notification laws?
No
Does the app collect or process data from minors (i.e., individuals under the age of 16)?
No
Does the app have capabilities to delete an individual's personal data upon request?
N/A
Does the app have capabilities to restrict or limit the processing of an individual's personal data upon request?
N/A
Does the app provide individuals the ability to correct or update their personal data?
N/A
Are regular data security and privacy reviews performed (for example, Data Protection Impact Assessments or privacy risk assessments) to identify risks related to the processing of personal data for the app?
N/A
Questions
Questions or updates to any of the information you see here? Contact us!
Information
Response
Does your application integrate with Microsoft identity platform (Microsoft Entra ID) for single-sign on, API access, etc.?
Yes
Have you reviewed and complied with all applicable best practices outlined in the Microsoft identity platform integration checklist?
Yes
Does your app use the latest version of MSAL (Microsoft Authentication Library) or Microsoft Identity Web for authentication?
Yes
Does your app support Conditional Access policies?
No
Does your app support Continuous Access Evaluation (CAE)
No
Does your app store any credentials in code?
No
Apps and add-ins for Microsoft 365 might use additional Microsoft APIs outside of Microsoft Graph. Does your app or add-in use additional Microsoft APIs?
No
Data access using Microsoft Graph
Graph Permission
Permission Type
Justification
Microsoft Entra App ID
Calendars.ReadWrite
application
The app can create entries in the calendars of users.
The system enforces permissions to book resources. Permissions can be based on single users defined or groups. For the selection of groups to be allowed to book a certain resource, our system calls the Graph API to get the groups, which users are allowed to access.
Multiple reasons: 1-to read out working hours of users for us to prepopulate from/to timeframes for bookings, 2) to read the timezone information of a user, to create bookings in the correct timezone of the user, 3) to get the locale of the user, to be able to send emails when booking for a different person and when cancelling bookings.