Privacy Policy

Effective date: When posted on the Site

Last updated: August 5, 2026

Privacy requests: Submit through the Contact page on oreabyjulie.com

Business mailing address: 7284 W. Palmetto Park Road, Suite 101, Boca Raton, Florida 33433

European representative: If appointment is required, current contact details will be published on this page before the relevant processing begins.

1. Who We Are and Scope

1.1 Controller. OREA Events LLC, a Florida limited liability company using the OREA by Julie brand ("OREA," "we," "us," or "our"), determines how and why personal information is processed for its website, inquiries, consultations, client engagements, event planning, marketing, and business administration, except where another party independently determines its own processing.

1.2 Scope. This Privacy Policy applies to oreabyjulie.com and related OREA-controlled pages, inquiry and consultation processes, client and prospect communications, event-planning services, client portals, newsletters, and other interactions that reference this Policy.

1.3 Other Parties. Venues, Vendors, hotels, carriers, payment processors, social networks, and other third parties may process personal information under their own notices. OREA does not control their independent practices.

1.4 Engagement-Specific Terms. A signed client agreement, corporate data addendum, Vendor contract, or consent form may contain additional privacy terms. If a more protective engagement-specific term conflicts with this Policy, that term controls for the relevant processing unless law requires otherwise.

2. Personal Information We Collect

Depending on how you interact with OREA, we may collect the following categories:

Category Examples
Identity and contact Name, email, telephone number, mailing address, company, job title, preferred language, and contact preferences.
Inquiry and event Event type, date, location, Venue, estimated budget, guest count, service interests, priorities, and information submitted in an inquiry or consultation.
Client and contract Signed agreements, signatures, billing contacts, approvals, meeting notes, scope, change requests, correspondence, and service history.
Financial and transaction Invoices, payment status, transaction identifiers, bank/wire details when needed, expense records, and tax information. Full card details are intended to be handled by a payment provider rather than stored directly by OREA.
Guest and attendee Guest lists, contact details, RSVP status, table or room assignments, travel/logistics information, dietary restrictions, accessibility needs, emergency contacts, and related event preferences.
Limited sensitive information Health, allergy, mobility, religious dietary, or other sensitive information voluntarily provided and reasonably needed for accommodation, safety, or Event logistics.
Vendor and partner Vendor contacts, proposals, insurance/licensing documents, contracts, payment milestones, service details, and performance communications.
Communications Email, text, call notes, portal messages, survey responses, preferences, complaints, and support requests.
Media and content Photographs, video, audio, testimonials, event details, and portfolio permissions, subject to contract and consent.
Device and website IP address, browser, device, operating system, timestamps, referring pages, pages viewed, approximate location derived from IP, cookie identifiers, and analytics or consent records.
Security and compliance Login events, access logs, fraud or abuse indicators, incident records, identity-verification information, and records needed to establish, exercise, or defend legal rights.
Recruitment and contractor Resume, work history, references, skills, availability, compensation, tax/identity documentation, background or insurance information when lawfully obtained, and work-product records.

We ask that you not provide personal information that is not reasonably needed for the stated purpose.

3. Sources of Personal Information

  • Directly from you through forms, calls, email, meetings, contracts, portals, payments, and Event communications.

  • From a client or authorized representative who provides guest, attendee, employee, family, or stakeholder

    information.

  • From Venues, Vendors, hotels, local partners, and other Event participants.

  • From website, analytics, consent-management, security, scheduling, email, and social-media technologies.

  • From public sources, referrals, professional networks, and lawful business databases.

  • From OREA personnel and contractors in the course of planning and performing Services.

4. How and Why We Use Personal Information

Purpose Activities Possible legal basis where GDPR applies
Respond to inquiries and take precontract steps Review requests, schedule consultations, prepare proposals, assess availability and fit. Steps requested before a contract; legitimate interests; consent where required.
Perform client engagements Onboard clients; plan, coordinate, staff, and document Events; communicate with Client, Venue, Vendors, guests, and stakeholders. Contract; legitimate interests; consent for optional processing.
Manage guests and accommodations Coordinate invitations, RSVP/logistics, room blocks, transport information, dietary and accessibility needs, and emergency contacts when included. Contract/legitimate interests; explicit consent or another lawful condition for sensitive data where required.
Process payments and administer accounts Invoice, receive payment confirmations, reimburse expenses, maintain books, and prevent fraud. Contract; legal obligation; legitimate interests.
Operate and secure systems Provide Site/portal functions, authenticate users, troubleshoot, protect accounts, monitor misuse, back up data, and respond to incidents. Legitimate interests; legal obligation; consent for nonessential device access where required.
Improve services and experience Analyze service patterns, Site performance, inquiries, surveys, and operational outcomes; develop templates and training using de-identified or minimized information where practical. Legitimate interests; consent where required.
Marketing and relationship management Send newsletters, journal updates, service information, and consultation invitations; maintain suppression lists. Consent or legitimate interests as permitted; right to opt out.
Media and portfolio use Use approved photographs, video, testimonials, and Event details in selected channels. Separate consent or written authorization; legitimate interests only for non-identifiable internal use.
Legal, insurance, and compliance Comply with law and contracts; maintain records; respond to claims, audits, subpoenas, and insurance matters; protect rights and safety. Legal obligation; legitimate interests; establishment, exercise, or defense of claims.
Recruit and manage personnel Evaluate and engage employees/contractors; administer work, compensation, confidentiality, access, and compliance. Precontract steps; contract; legal obligation; legitimate interests.

The applicable legal basis depends on the context and jurisdiction. We will not rely on consent where another legal basis is mor appropriate, and where we rely on consent you may withdraw it as described below

5. Guest, Attendee, and Sensitive Information

5.1 Client Responsibility. A client or organization providing another person's information is responsible for ensuring it has authority and any required legal basis, notice, or consent. OREA may rely on that representation unless OREA knows otherwise.

5.2 Data Minimization. We seek only information reasonably needed for Event planning, accommodation, safety, or logistics. Clients should not send full medical records, diagnoses, passport copies, government identifiers, payment- card data, or other highly sensitive material unless OREA specifically requests it through an appropriate channel.

5.3 Dietary, Accessibility, and Health Information. We may process limited allergy, dietary, mobility, accessibility, or health-related information voluntarily supplied for accommodation. We restrict it to appropriate personnel and Vendors, use it for the stated Event purpose, and seek to delete or de-identify it promptly after the Event unless retention is necessary for safety, claims, law, or an ongoing relationship.

5.4 Emergencies. In a genuine emergency, information may be used or disclosed as reasonably necessary to protect vital interests, contact emergency services, or comply with lawful directions.

6. How We Disclose Personal Information

We may disclose personal information to the following recipients for the purposes described in this Policy:

  • OREA personnel, event-day staff, independent contractors, and local coordinators with a need to know.

  • Venues, caterers, florists, designers, rental/production teams, photographers, videographers, entertainers, hotels,

    transport providers, security, childcare, accessibility, and other Vendors selected or approved for the Event.

  • Website hosting, CRM, cloud storage, email, communications, scheduling, e-signature, payment, accounting,

    analytics, consent-management, security, and IT service providers.

  • Professional advisers, including attorneys, accountants, auditors, insurers, brokers, and consultants.

  • A client's authorized representatives, family members, employees, speakers, or stakeholders where reasonably

    necessary for the engagement.

  • Government, courts, regulators, law enforcement, emergency services, or others when required by law or

    reasonably necessary to protect rights, safety, and security.

  • A buyer, investor, lender, successor, or adviser in connection with a proposed or completed merger, financing,

    reorganization, or sale, subject to appropriate confidentiality and applicable law.

Other recipients at your direction or with your consent.


6.1 No General Sale for Money. OREA does not intend to sell personal information for monetary consideration. Some advertising or analytics technologies can be treated as a 'sale,' 'sharing,' or targeted advertising under certain laws; OREA will configure and disclose such technologies, and offer required choices, before using them.

6.2 Vendor Independence. Some Venues and Vendors are independent controllers or businesses with their own purposes, legal duties, and privacy notices. OREA is not responsible for their independent processing.

7. Cookies and Similar Technologies

7.1 What They Are. The Site may use cookies, pixels, local storage, software development kits, and similar technologies to operate, remember choices, measure use, secure forms, and support communications or marketing.

Category Purpose Treatment
Strictly necessary Security, network management, consent choices, form operation, and features requested by the visitor. Generally active because needed for the Site or requested service.
Functional / preference Remember language, region, display, or user choices. Consent where required; otherwise based on requested functionality or legitimate interests.
Analytics Understand traffic, pages, performance, and use patterns. Disabled until valid consent where required; configured to minimize data where practical.
Advertising / social Measure campaigns, support embedded social features, or personalize advertising. Disabled until valid consent where required; may be omitted at launch.

7.2 Consent Tool. Where required, nonessential technologies remain disabled until you make an affirmative choice. The banner or preference center provides reasonably equivalent accept and reject options and a persistent way to change or withdraw consent.

7.3 Browser Controls. You may also control cookies through browser settings, but blocking necessary technologies may impair Site functions. Browser controls do not always affect pixels, server logs, or other technologies.

7.4 Third-Party Tools. Final cookie details, providers, durations, and purposes will be listed in the Site's preference center or cookie notice after OREA's technology stack is finalized.

7.5 Preference Signals. The Site does not currently respond to browser 'Do Not Track' signals, for which no uniform standard exists. Where a legally recognized opt-out preference signal, such as Global Privacy Control, applies to OREA's processing, OREA will honor it as required by law.

8. Marketing Communications

8.1 Email Marketing. We may send newsletters, planning insights, company updates, or consultation invitations where we have consent or another lawful basis. Each marketing email will include an unsubscribe method or instructions.

8.2 Text Messages. We do not currently plan significant SMS marketing. If introduced, we will use an appropriate consent process and provide required opt-out instructions. Event logistics, appointment reminders, and urgent operational messages are not marketing solely because they are sent by text.

8.3 Opt-Out. You may opt out of marketing at any time. We may retain limited contact information on a suppression list to honor the opt-out and may continue transactional or service communications.

9. International Data and Transfers

9.1 United States Operations. OREA is based in Florida, and personal information may be processed in the United States and other countries where OREA, its personnel, Venues, Vendors, or service providers operate. Those countries may have different data-protection laws.

9.2 Transfer Safeguards. Where European Economic Area personal data is transferred to a country without an applicable adequacy decision and GDPR transfer rules apply, OREA will use an available lawful mechanism appropriate to the transfer, such as the European Commission's standard contractual clauses, a valid adequacy framework, or another permitted safeguard, together with supplementary measures where appropriate.

9.3 Event Vendors. Client understands that Event planning may require information to be shared with independent Venues or Vendors in the Event country or the United States. OREA will seek to minimize the information and identify material cross-border workflows during engagement setup.

9.4 EU Representative. If GDPR Article 27 requires OREA to appoint a representative in the European Union, OREA will publish the representative's identity and contact details before the relevant processing begins. This determination remains subject to the final EU service and data model.

10. Data Retention

We retain personal information only as long as reasonably necessary for the purposes described, contractual and professional needs, legal, accounting, insurance, dispute-resolution, and security requirements.

Record Retention approach
Unconverted inquiries / consultation records Up to 24 months after last substantive interaction, unless a shorter request applies or a longer period is needed for a claim.
Client contracts, scope, approvals, and core project records Generally 7 years after engagement close, subject to tax, insurance, claim, and local-law needs.
Accounting, invoices, and transaction records Generally 7 years or the period advised by OREA's accountant.
General guest lists and logistics Delete or de-identify within 90 days after the Event unless a longer period is required by law, requested by Client, needed for a continuing engagement, or reasonably necessary for a claim or incident.
Dietary, accessibility, and limited health information Target deletion or de-identification within 90 days after the Event unless needed for a continuing engagement, incident, claim, or legal duty.
Marketing contacts Until opt-out, inactivity cleanup, or withdrawal; suppression records may be kept longer to honor the choice.
Media permissions and portfolio records Retain while the related media is used and for 7 years after the last use, subject to withdrawal terms, legal holds, and rights documentation.
Website and security logs According to provider settings and security needs, commonly a limited rolling period; exact periods to be documented after configuration.
Contractor / recruitment records For the engagement or recruitment purpose and applicable employment, tax, insurance, and claim periods.
Backups Until overwritten under the ordinary backup cycle, with restricted use and deletion from active systems first.

10.1 Legal Holds. We may suspend deletion when information is reasonably needed for a dispute, investigation, audit, insurance matter, or legal obligation.

10.2 De-Identification. We may retain information that has been aggregated or de-identified so that it is not reasonably linked to an identifiable person, subject to applicable law.

11. Security

11.1 Safeguards. We use reasonable administrative, technical, and physical measures appropriate to the nature of the information, which may include access controls, multifactor authentication, vendor review, device security, encrypted transmission/storage where supported, backups, confidentiality terms, and incident procedures.

11.2 No Absolute Security. No method of transmission, storage, or security is guaranteed. You should use secure channels, protect credentials, independently verify unusual payment instructions, and avoid sending unnecessary sensitive information.

11.3 Incident Response. If we determine that a security incident requires notice, we will provide notice and take other steps as required by applicable law. Vendors and contractors are expected to report relevant incidents promptly so OREA can assess obligations.

12. Your Privacy Rights

12.1 General Requests. You may request access, correction, deletion, or a copy of personal information and may object to or restrict certain uses, depending on where you live and applicable law. You may also opt out of marketing and withdraw consent for future processing.

12.2 EEA Rights. Where GDPR applies, you may have rights to access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interests or direct marketing, withdrawal of consent without affecting prior lawful processing, and complaint to a competent supervisory authority.

12.3 Automated Decisions. OREA does not currently make decisions that produce legal or similarly significant effects solely through automated processing. If that changes, OREA will provide required information and rights.

12.4 How to Submit. Send a request to the Contact page on oreabyjulie.com with your name, relationship to OREA, requested right, and enough detail to locate the information. Do not send a copy of a government ID unless OREA specifically requests an appropriate verification method.

12.5 Verification and Agents. We may verify identity and authority to protect privacy. An authorized agent may submit a request where permitted, but we may request proof of authorization and direct confirmation from the individual.

12.6 Timing and Exceptions. We will respond within the period required by applicable law. Rights may be limited by legal privilege, another person's rights, recordkeeping obligations, security, legal claims, disproportionate effort, or other lawful exceptions. We will explain a denial where required.

12.7 No Discrimination. OREA will not unlawfully discriminate against a person for exercising an applicable privacy right.

12.8 Supervisory Authority. An EEA individual may complain to the data-protection authority in the country of habitual residence, work, or alleged infringement. We encourage contacting OREA first so we can try to address the concern.

13. Children and Minors

13.1 Website. The Site is not directed to children, and we do not knowingly collect personal information directly from a child through a general Site form without appropriate authorization.

13.2 Event Guests. A client may provide limited information about minor guests for seating, meals, accessibility, emergency, or Event logistics. The client is responsible for lawful authority and notice. OREA will limit use to the Event purpose and appropriate recipients.

13.3 Media. Identifiable media involving a minor requires the authorization process stated in the applicable Media and Marketing Authorization and any additional parent/guardian consent required by law or contract.

14. Photography, Video, and Testimonials

14.1 Consent Model. OREA uses identifiable client, guest, corporate, or private-event content for portfolio, advertising, publicity, or social media only under a separate written Media and Marketing Authorization or other written consent that specifically covers the use. Silence is not treated as consent.

14.2 Operational Records. Limited visual or written records may be retained for planning, safety, quality control, insurance, dispute, or legal purposes and are not used for marketing without authorization.

14.3 Vendor Media. Photographers, Venues, and other Vendors may have independent contractual rights and privacy practices. Questions about their use should be directed to the relevant Vendor.

15. Third-Party Sites and Services

15.1 Independent Notices. Links, embedded content, social pages, payment systems, mapping tools, and Vendor websites are governed by the third party's terms and privacy notice. Review them before providing information.

15.2 Social Media. Information posted publicly or shared with a social platform may be visible, copied, or used by others. OREA does not control platform processing.

15.3 Current and Expected Service Providers

OREA expects to use the providers below for the stated functions. A provider listed as conditional is used only if enabled or adopted. Providers may process information under their own terms and may use approved subprocessors. OREA will update this Policy if its material provider practices change.

Function Provider(s) Information / purpose
Website and forms Squarespace Hosting, pages, inquiry forms, embedded content, and site security.
Planning, CRM, contracts and portal Aisle Planner Prospect/client records, proposals, contracts, project plans, files, communications, and portal access.
Payments Stripe Hosted payment processing, payment status, fraud prevention, and transaction records; OREA does not intend to store full card numbers.
Business email, files, calendar and meetings Google Workspace, Google Drive, Google Calendar and Google Meet Communications, documents, scheduling, collaboration, and video meetings.
Scheduling Calendly Consultation and meeting scheduling, availability, reminders, and submitted contact information.
Meeting assistance Granola, when used Meeting audio access, transcripts, notes, and summaries. OREA will provide notice and obtain consent where required before recording or AI-assisted processing.
Analytics and tag management Google Analytics 4; Google Tag Manager if installed; Google Search Console Site performance, traffic and search information. Nonessential technologies remain subject to the Site consent tool where required.
Email marketing Flodesk Newsletter subscriptions, campaign delivery, engagement, preferences, and unsubscribe records.
Team communication Slack Internal project communication and limited shared information based on access settings.
Video meetings Zoom, if used Video meetings, meeting metadata, and optional recordings only with appropriate notice/permission.
Social and business profiles Instagram, Facebook, Pinterest, LinkedIn and Google Business Profile Public profiles, messages, referrals, audience insights, and platform interactions.
Wedding directories The Knot when live; WeddingWire if used Business listings, leads, reviews, and referral activity.

16. Changes to This Policy

16.1 Updates. We may update this Policy to reflect changed practices, providers, law, or Services. We will post the updated version and change the 'Last updated' date. Where required, we will provide additional notice or seek consent for a materially different use.

16.2 Prior Versions. A signed client agreement or consent is not retroactively expanded solely by a website-policy update. We may retain prior versions for compliance records.

17. Contact Us

Privacy questions, rights requests, and complaints may be sent to:

OREA Events LLC
Using the OREA by Julie brand
7284 W. Palmetto Park Road, Suite 101
Boca Raton, Florida 33433
Privacy requests: Contact page on oreabyjulie.com Website: oreabyjulie.com

European representative: If one is appointed under applicable law, current contact details will be published on oreabyjulie.com.