Privacy policy
Last updated: 9 October 2026
This privacy policy explains how Group Calendar Bridge (the "app"), a Microsoft Teams app published by Elektraset, s.r.o. ("we", "us"), handles data. The app is available at https://group-calendar-bridge.apps.elektraset.com.
Summary
- The app shows the calendar of the Microsoft 365 Group of a team inside Microsoft Teams.
- The app reads and, when a team owner turns on editing, writes calendar events only on behalf of the signed-in user, with Microsoft Graph delegated permissions.
- We do not store calendar events, attendees, messages or files. We do not sell data, and we do not use data for advertising or for training AI models.
Who is the controller
For the calendar data in your Microsoft 365 tenant, your organization is the controller and we act as a processor. For the small set of operational data that our server handles (see below), the controller is Elektraset, s.r.o., website https://elektraset.com/, email help@elektraset.com.
What data the app handles
- Sign-in token. Microsoft Teams gives the app a single sign-on token for the signed-in user. Our server checks it and exchanges it with Microsoft Entra ID for a Microsoft Graph token (On-Behalf-Of flow). The tokens are held in server memory only, for at most their lifetime (about one hour), and are never written to disk or logs.
- Calendar data. When you open the tab, our server requests the events of the group calendar for the dates on screen from Microsoft Graph and passes them to your browser. Event data (subject, times, location, organizer, attendees, categories, description, meeting links) passes through the server in memory and is not stored.
- Events that you create or edit. When editing is turned on, the data that you enter is sent to Microsoft Graph and saved in your group calendar in Microsoft 365. We do not keep a copy.
- Browser settings. Your browser stores your chosen time zone and your category filter in its local storage. They never leave your device.
- Operational logs. Our hosting keeps technical logs (time, request path, HTTP status, error messages) for up to 30 days to run and secure the service. The logs contain no calendar content and no tokens.
Microsoft Graph permissions
The app uses delegated permissions only: User.Read (sign-in), Group.Read.All (read the group calendar) and, optionally, Group.ReadWrite.All (create, edit and delete group events). The app calls only the calendar of the group of the team in which the tab is open. Because the permissions are delegated, a user can only see or change calendars that the user can already access in Outlook.
Sharing
We do not share, sell or rent data. The data goes only between your browser, our server and Microsoft (Microsoft Entra ID and Microsoft Graph). Our hosting provider runs the server for us and has no access rights to the data beyond running it.
Security
All traffic uses HTTPS. The server checks the signature, audience, issuer and tenant of every sign-in token. We keep the app's credentials secret and rotate them.
Retention and deletion
We keep no calendar data, so there is nothing to delete on our side. To stop all access, an admin of your organization can remove the app in the Teams admin center and remove its consent in the Microsoft Entra admin center (Enterprise applications).
Your rights
Under the GDPR and other laws you can ask for access, correction, deletion, restriction or portability of personal data, and you can object or complain to a supervisory authority (in the Czech Republic: the Office for Personal Data Protection, https://uoou.gov.cz/). Contact us at help@elektraset.com.
Children
The app is for work and school accounts in organizations. It is not directed at children.
Changes
We will publish changes to this policy on this page and update the date above.
Contact
Elektraset, s.r.o. · https://elektraset.com/ · help@elektraset.com