Privacy Policy for the onesto App for Microsoft Teams Business travel management within Microsoft Teams

Scroll down

Privacy Policy for the onesto App for Microsoft Teams

 

Last updated: 30 July 2026

 

The onesto app for Microsoft Teams provides authenticated access to the standard onesto business travel management web application within Microsoft Teams. It enables authorized users to search, book and manage business travel, uses Microsoft single sign-on, and allows users to share selected reservation information and travel search results with colleagues through Microsoft Teams. This policy explains how personal information is handled when users access or use the onesto app and the underlying onesto service.

 

1. Scope

This Privacy Policy applies to the onesto app for Microsoft Teams and to the underlying onesto service when it is accessed through Microsoft Teams. The Teams app displays the standard authenticated onesto web application inside Microsoft Teams and adds Microsoft single sign-on and Teams-based sharing and notification functions. The policy applies whenever onesto processes personal information in connection with providing, securing, supporting or improving these functions.

The features available to an individual user depend on the services selected and configured by the user's employer or other contracting organization (the "Customer").

 

2. Responsibility for Personal Information

In most Customer deployments, the Customer determines why and how personal information is processed for business travel purposes and acts as the data controller. onesto GmbH processes that information on the Customer's behalf and according to the Customer's instructions. For limited activities for which onesto GmbH determines the purposes and means of processing, such as protecting its systems, managing direct support contacts or meeting legal obligations, onesto GmbH may act as an independent controller.

Questions about the Customer's travel program, account configuration or exercise of privacy rights should normally be directed first to the Customer. onesto GmbH supports Customers in responding to valid privacy requests.

 

3. Personal Information We Process

Depending on the Customer's configuration, the features used and the travel services requested, onesto may process the following categories of personal information:

  • Identity and contact information: name, business email address, telephone number, postal address and account credentials or identifiers.
  • Microsoft single sign-on information: the Microsoft Entra tenant identifier (tid), the user's Microsoft login name (preferred_username), the user's Microsoft Entra object identifier (oid), and the token audience (aud) used to confirm that the token was issued for the onesto app.
  • Employment and administrative information: employee number, company, department, cost center, organizational unit, approver, travel policy and other information required to administer a Customer's travel program.
  • Travel profile and preference information: preferred airports or stations, seating and meal preferences, accessibility requests, frequent-traveler or loyalty program details and supplier account information.
  • Travel and booking information: search requests, reservations, ticketing data, itineraries, changes, cancellations, travel dates, destinations, travel companions and related communications.
  • Payment-related information: payment method or payment-related information required to complete a booking. The exact data processed depends on the payment method and the Customer's setup.
  • Expense and user-provided content: expense type and amount, receipts, photographs, documents and other content submitted through enabled document-management or travel-expense functions.
  • Technical and usage information: IP address, browser and Teams client information, operating system, timestamps, session and authentication information, diagnostic data and information about use of the service.
  • Teams sharing and notification information: the reservation information, travel search results, notification preview text, references and links that a user chooses to share with colleagues through Microsoft Teams.
  • Support information: messages, contact details and information provided when a user or Customer contacts support.

 

4. How We Obtain Personal Information

Personal information may be obtained:

  • directly from the user when an account or travel profile is completed, a booking is made, content is uploaded or support is contacted;
  • from the Customer, for example through human-resources, identity-management, travel-policy or administrative systems;
  • from Microsoft Teams and Microsoft Entra ID when a user signs in, including the token claims described in Section 7;
  • from travel agencies, travel management companies, booking providers, airlines, rail operators, hotels, rental-car providers and other suppliers involved in arranging or servicing travel; and
  • automatically when the user accesses the service, including technical, security and usage information.

 

5. How We Use Personal Information

onesto processes personal information as necessary to:

  • validate the Microsoft Teams token, identify the Customer tenant and user, match the Microsoft identity to an authorized onesto account, establish the user session and provide access to the service;
  • search, book, ticket, modify, cancel and otherwise manage business travel services;
  • synchronize itineraries and provide booking confirmations, travel updates, delay information, security notices and administrative messages;
  • share user-selected reservation information or travel search results with selected colleagues and send related Microsoft Teams activity feed notifications;
  • apply the Customer's travel policies, approval workflows, cost allocation and, where enabled, travel-expense processes;
  • provide customer service, technical support, maintenance and service communications;
  • detect, prevent and investigate fraud, unauthorized access, security incidents and other unlawful or harmful activity;
  • monitor service performance, troubleshoot technical problems and improve the reliability, functionality and user experience of onesto; and
  • comply with legal obligations, enforce agreements and establish, exercise or defend legal claims.

 

6. Legal Bases Where the GDPR Applies

When onesto processes personal information on behalf of a Customer, the Customer determines the applicable legal basis. When onesto GmbH acts as controller, processing is based, as applicable, on performance of a contract or steps taken before entering into a contract, compliance with a legal obligation, legitimate interests that are not overridden by the individual's rights and interests, or consent where consent is required by law. Consent may be withdrawn at any time without affecting processing that occurred before withdrawal.

 

7. Microsoft Teams Single Sign-On and Permissions

The onesto app uses a Microsoft Teams JSON Web Token (JWT) for automatic single sign-on. The following claims from the token are processed for authentication and session handling:

  • tid (Tenant ID): identifies the Microsoft Entra tenant and is used to determine the relevant Customer context.
  • preferred_username: contains the user's Microsoft login name and is used to identify or match the user to an authorized onesto account.
  • oid (Object ID): is the internal Microsoft Entra object identifier used to distinguish the user within the tenant.
  • aud (Audience): identifies the intended recipient application and is checked to confirm that the token was issued for the onesto app.

 

8. Sharing of Personal Information

The Teams integration allows a user to initiate sharing of selected reservation information or travel search results with colleagues. The initiating user selects the information and the available recipient scope. Depending on that selection, onesto may create a Teams activity feed notification for an individual user, users in a chat or users in a team. The notification may contain selected information or a reference or link that enables an authorized recipient to open the relevant content in onesto.

Information sent through Microsoft Teams is also processed within the Customer's Microsoft 365 environment and is subject to the Customer's Teams configuration and Microsoft's applicable terms and privacy practices. Users should share travel information only with authorized recipients.

onesto does not sell or rent personal information. Personal information may otherwise be disclosed only as necessary for the purposes described in this policy and according to the Customer's configuration, including to:

  • the Customer and its authorized administrators, approvers, travel managers and other authorized users;
  • Microsoft, as the provider of Microsoft Teams, Microsoft Entra ID and the Microsoft 365 environment through which single sign-on and Teams notifications are provided;
  • travel agencies, travel management companies and business-travel partners;
  • airlines, rail operators, hotels, rental-car providers, booking and distribution systems, payment providers and other suppliers needed to search, reserve, purchase or support travel;
  • hosting, infrastructure, communications, security, support and other service providers that process information under appropriate contractual and confidentiality obligations; and
  • courts, supervisory authorities, law-enforcement bodies or other recipients when disclosure is required by law or necessary to protect legal rights, users or the service.

 

9. International Data Transfers

Business travel may involve suppliers and destinations outside the country in which the user or Customer is located. Personal information may therefore be processed in other countries when this is necessary to arrange or support travel. Where onesto is responsible for a transfer from the European Economic Area to a country without an adequacy decision, it uses an appropriate legal transfer mechanism and additional safeguards where required.

 

10. Data Retention

Personal information is retained for as long as necessary to provide the onesto service, comply with the Customer's instructions and contractual requirements, complete and document travel transactions, meet legal, tax, accounting and security obligations, and resolve disputes. Retention periods vary according to the type of information, the Customer's configuration and applicable law. When information is no longer required, it is deleted or anonymized in accordance with applicable requirements and established retention procedures.

 

11. Security

onesto uses appropriate technical and organizational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These measures are reviewed and improved in line with technological developments, the nature of the information and the risks presented by the processing. No method of transmission or storage can be guaranteed to be completely secure.

 

12. User Choices and Privacy Rights

Some profile information may be viewed or updated within onesto, depending on the Customer's configuration. A user decides whether to use the Teams sharing function and which available recipients receive the selected information. Installation, consent and Microsoft Teams permissions may be managed by the user or the Customer's Microsoft 365 administrator, depending on the permission scope and the Customer's configuration.

Where provided by applicable law, individuals may have rights to request access to, correction of, deletion of or restriction of processing of personal information; receive certain information in a portable format; object to processing based on legitimate interests; and withdraw consent. Individuals may also lodge a complaint with a competent data protection authority.

Because the Customer is usually the controller of information processed through onesto, privacy requests should normally be submitted to the Customer. Requests may also be sent to the onesto data protection contact below. onesto will route or support the request as appropriate and may need to verify the requester's identity.

The supervisory authority responsible for onesto GmbH in Bavaria is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany.

 

13. Children

onesto is a business service intended for authorized users of Customer organizations. It is not directed to children under 16, and onesto GmbH does not knowingly collect personal information directly from children under 16 through the service without appropriate authorization.

 

14. Changes to This Privacy Policy

This Privacy Policy may be updated to reflect changes to the onesto service, legal requirements or privacy practices. The date at the beginning of the policy identifies the latest revision. Material changes will be communicated through an appropriate channel where required.

 

15. Contact

For questions about this Privacy Policy or the processing of personal information by onesto GmbH, contact:

Company: onesto GmbH
Address: Augsburger Str. 14, 86551 Aichach, Germany
Data protection email: datenschutz@onesto.de