Privacy policy

Last updated: 2 August 2026

1. About This Privacy Policy

This Privacy Policy explains how Ali Saad, ABN 29 716 299 765, trading as Orélinia (“Orélinia”, “we”, “us” or “our”) collects, holds, uses, discloses and protects personal information.

It applies when you:

  • Visit or interact with our website.
  • Submit an enquiry or request a quotation.
  • Contact us by telephone, email, SMS, WhatsApp or social media.
  • Make or manage a booking.
  • Attend an event at which Orélinia provides services.
  • Deal with us as a venue, contractor, supplier or independent business partner.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent they apply to our activities. Where the small-business exemption or another exemption applies, we nevertheless seek to handle personal information consistently with the principles described in this Policy.

This Privacy Policy is a notice about our information-handling practices. It is not a contract and does not replace any collection notice, quotation, booking agreement or Terms and Conditions that applies to a particular interaction.

2. Personal Information We Collect

The personal information we collect depends on how you interact with us and what is reasonably necessary for the relevant event or business purpose.

2.1 Identity and Contact Information

This may include:

  • Full name.
  • Email address.
  • Telephone or WhatsApp number.
  • Residential, delivery, billing or event address.
  • Business name and role.
  • Details of an authorised representative or event contact.

2.2 Event and Booking Information

This may include:

  • Event type, date and times.
  • Venue and installation location.
  • Guest numbers and seating requirements.
  • Site dimensions, access conditions and photographs.
  • Styling, equipment, catering, beverage and production preferences.
  • Setup, pack-down and collection requirements.
  • Venue rules, supplier details and operational instructions.
  • Information relevant to safety, accessibility or event delivery.

2.3 Transaction and Payment Information

This may include:

  • Quotation, invoice and payment records.
  • Booking Payment and security-bond information.
  • Billing details.
  • Bank-account details provided for an approved refund or bond return.
  • Transaction references and payment status.

Card payments are processed by third-party payment providers. Orélinia does not intentionally store complete payment-card numbers or card security codes.

2.4 Communications and Service Records

This may include:

  • Enquiries, messages and correspondence.
  • Notes of telephone calls or meetings.
  • Client instructions, approvals and variations.
  • Complaints, incident reports and supporting evidence.
  • Feedback, reviews and survey responses.

2.5 Images and Event Media

We may collect photographs or video of a site, hired equipment, completed installations and event work. Our Terms and Conditions explain how installation and portfolio images may be used and how a Client may object before the event.

We do not intentionally use identifiable close-up images of guests or children for marketing without appropriate permission.

2.6 Technical and Website Information

When you use our website or digital services, we or our service providers may collect:

  • IP address.
  • Device, browser and operating-system information.
  • Device or advertising identifiers.
  • Pages viewed and time spent on the website.
  • Links, buttons and forms used.
  • Referral source and campaign information.
  • Cookie, pixel and similar technology data.
  • Approximate location derived from an IP address.
  • Website diagnostics, error and security logs.

2.7 Sensitive Information

Event planning may occasionally require limited sensitive information, such as allergy, dietary, disability, accessibility, health or safety information. We collect sensitive information only where it is reasonably necessary and where you consent or another lawful basis applies.

Do not provide sensitive information that is not necessary for the event or requested by the responsible service provider.

3. How We Collect Personal Information

We may collect personal information:

  • Directly from you through forms, messages, calls, meetings, bookings and payments.
  • From a person authorised to act for you.
  • From venues, property owners, contractors or independent business partners involved in your event.
  • Through WhatsApp, Instagram, Facebook or another platform you use to contact us.
  • From referral sources or publicly available business information where lawful and relevant.
  • Automatically through cookies, pixels, analytics and website logs.

If you provide personal information about another person, you must be authorised to provide it and, where required, make that person aware of this Policy.

Where lawful and practicable, you may deal with us anonymously or using a pseudonym. This will generally not be practicable where we need to prepare a personalised quotation, verify authority, take payment, access a site or deliver an event.

4. Why We Collect and Use Personal Information

We may collect, hold, use and disclose personal information to:

  • Respond to enquiries and prepare quotations.
  • Confirm identity, authority and event instructions.
  • Assess event requirements, site access, safety and suitability.
  • Administer bookings, contracts, invoices, payments and security bonds.
  • Plan and deliver event hire, production and management services.
  • Coordinate venues, staff, contractors and independent business partners.
  • Arrange delivery, installation, event operations, pack-down and collection.
  • Produce approved personalised or custom items.
  • Provide service notices, reminders and booking updates.
  • Manage complaints, incidents, insurance matters and disputes.
  • Detect fraud, misuse, security threats or unlawful conduct.
  • Maintain business, financial, tax and operational records.
  • Comply with legal, regulatory, insurance and safety obligations.
  • Improve our services, systems, website and customer experience.
  • Conduct analytics and measure advertising performance.
  • Send direct marketing where permitted by law.

We may also use information for a related purpose that you would reasonably expect, where you consent, or where otherwise permitted or required by law.

5. If You Do Not Provide Information

You may choose not to provide personal information. However, if required information is not provided, we may be unable to prepare an accurate quotation, confirm a booking, process payment, assess the site, coordinate providers or safely deliver the requested services.

6. Cookies, Analytics and Advertising Technologies

Our website may use cookies, pixels, tags and similar technologies for:

  • Essential website functions.
  • Form submission and security.
  • Remembering preferences.
  • Website analytics and performance measurement.
  • Advertising attribution and campaign reporting.
  • Personalised advertising where permitted.

These technologies may include Google Analytics and Meta Pixel where enabled on our website. The providers of these technologies may collect information directly from your browser and handle it under their own privacy policies.

You can manage cookies through any consent controls made available on our website and through your browser settings. Blocking some cookies may affect website functionality. Advertising preferences may also be managed through the relevant platform’s settings.

Where tracking information amounts to personal information, we handle it in accordance with this Policy and applicable law.

7. Direct Marketing

We may send marketing by email, SMS, WhatsApp or another electronic channel only where we have the required consent or another lawful basis.

Marketing communications will identify Orélinia and provide a clear way to unsubscribe where required. You may withdraw consent or opt out at any time by:

  • Using the unsubscribe option in the message.
  • Replying STOP where that option is provided.
  • Contacting us using the details in section 17.

We will process an electronic-marketing unsubscribe request within the period required by law. Opting out of marketing does not prevent us from sending non-promotional messages needed to administer an existing enquiry, booking, payment, safety matter or legal obligation.

We do not sell or rent personal information. We do not provide Client contact details to independent business partners for their own direct marketing unless the individual has consented or the disclosure is otherwise permitted by law.

8. When We Disclose Personal Information

We may disclose personal information only where reasonably required for the purposes described in this Policy, including to:

  • Orélinia staff and authorised contractors.
  • Venues, property owners and site contacts.
  • Independent business partners and specialist suppliers involved in the approved event scope.
  • Delivery, logistics, installation and collection providers.
  • Payment processors, banks and accounting providers.
  • Website hosting, cloud storage, CRM, project-management and business-system providers.
  • Email, SMS, telephone, WhatsApp and other communications providers.
  • Analytics, advertising and social-media platforms.
  • Insurers, professional advisers, debt-recovery providers and dispute-resolution services.
  • Government agencies, regulators, courts, law-enforcement bodies or emergency services where required or permitted by law.

Independent business partners remain separate businesses. The accepted proposal should identify the provider responsible for each partner-delivered service and whether the Client contracts with Orélinia or directly with that provider.

Where a Client contracts directly with an independent provider, that provider handles personal information under its own privacy practices. Orélinia discloses only the information reasonably required for the approved coordination or service purpose.

9. Overseas Processing and Disclosure

Some service providers, cloud platforms, communications systems, analytics providers or authorised support personnel may store, process or access personal information outside Australia.

Likely locations may include Australia, Türkiye and the United States. Information may also be processed in other countries used by a provider’s infrastructure or subcontractors. Because global cloud and communications providers may change their processing locations, it may not be practicable to identify every country in advance.

Where the Australian Privacy Principles apply to an overseas disclosure, we take reasonable steps required by law before disclosing personal information to an overseas recipient.

10. Data Security and Data Breaches

We take reasonable technical, physical and organisational steps appropriate to the nature of the information we hold. These may include:

  • Access restrictions and role-based permissions.
  • Password and multi-factor authentication controls.
  • Secure cloud and payment providers.
  • Staff and contractor confidentiality requirements.
  • Device, account and system security measures.
  • Data minimisation, backup and recovery practices.
  • Procedures for responding to suspected privacy and security incidents.

No internet transmission or storage system is completely secure. We cannot guarantee absolute security.

If a data breach occurs, we will assess and respond to it. Where the Notifiable Data Breaches scheme applies and the legal threshold is met, we will notify affected individuals and the Office of the Australian Information Commissioner as required.

11. Data Retention

We retain personal information only for as long as reasonably required to:

  • Provide and administer the requested services.
  • Maintain booking, financial and operational records.
  • Meet tax, accounting, insurance and legal obligations.
  • Manage complaints, claims and disputes.
  • Protect legitimate business and legal interests.

Most business and tax records are generally retained for at least five years, although some records may need to be kept for a longer period.

When personal information is no longer required and no law, court order or legitimate permitted purpose requires its retention, we take reasonable steps to destroy it securely or de-identify it. Copies held in backups may remain until they are overwritten or securely removed through the relevant retention cycle.

12. Access, Correction and Deletion Requests

You may contact us to:

  • Request access to personal information we hold about you.
  • Ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
  • Request deletion or de-identification where the information is no longer required and may lawfully be removed.
  • Withdraw a consent you previously provided, subject to legal and contractual consequences.

We may need to verify your identity before acting on a request. We will use the minimum information reasonably necessary for verification.

We will respond within a reasonable period, ordinarily within 30 calendar days. Access or correction may be refused where permitted by law. If we refuse a request, we will provide written reasons and available complaint options where required.

Australian privacy law does not create an unrestricted right to deletion. We may retain information where required for tax, accounting, insurance, contractual, dispute, safety or other lawful purposes.

13. Privacy Complaints

To make a privacy complaint, contact us using the details in section 17 and include:

  • Your name and preferred contact details.
  • A clear description of the concern.
  • Relevant dates, communications or supporting material.
  • The outcome you are seeking.

We will acknowledge and investigate the complaint and aim to provide a response within 30 calendar days. If additional time is reasonably required, we will explain the reason for the delay.

If you are not satisfied with our response and the Privacy Act applies to the matter, you may contact the Office of the Australian Information Commissioner through www.oaic.gov.au.

14. Children and Information About Other People

Our services may involve family events or events attended by children. We do not knowingly request personal information directly from a child where it would be more appropriate to deal with a parent, guardian or authorised adult.

Information about a child should be provided only by a parent, guardian or person authorised to provide it, and only where reasonably necessary for the event.

If you believe that personal information about a child has been provided without appropriate authority, contact us so that we can assess and address the matter.

15. Social Media and External Links

Our website and communications may link to external websites or social-media platforms. Those services operate under their own terms and privacy policies. Orélinia is not responsible for the privacy practices of an external service that it does not control.

Information submitted through a social-media platform may be accessible to that platform before it reaches Orélinia. Review the platform’s privacy settings and policy before providing personal information.

16. Automated Decision-Making

Orélinia may use calculators, quote builders, workflows or software-assisted tools to organise information and prepare estimates. These tools support staff and operational processes.

Orélinia does not currently arrange for a computer program to make decisions using personal information where those decisions could reasonably be expected to significantly affect an individual’s rights or interests without appropriate human involvement.

17. Contact Us

For privacy enquiries, access or correction requests, marketing opt-outs or complaints, contact:

Privacy Officer
Orélinia Event Hire
Ali Saad, ABN 29 716 299 765
Email: info@orelinia.com.au
Phone/WhatsApp: +61 450 015 069
Location: Sydney, New South Wales, Australia

18. Changes to This Policy

We may update this Privacy Policy when our services, systems, providers or legal obligations change.

The current version will be published on our website with a revised “Last updated” date. A later version applies from its stated update date and does not retrospectively alter how an earlier matter was handled.

This document is a commercially structured draft and not legal advice. It should be reviewed by a qualified Australian privacy or commercial lawyer before being published as Orélinia’s final legal policy.