PAIA Manual
Meridian Studio (Pty) Ltd. Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (as amended).
Date of compilation: 9 August 2026.
1. List of acronyms and abbreviations
- "CIO" Chief Information Officer
- "DIO" Deputy Information Officer
- "IO" Information Officer
- "Minister" Minister of Justice and Correctional Services
- "PAIA" Promotion of Access to Information Act No. 2 of 2000 (as amended)
- "POPIA" Protection of Personal Information Act No. 4 of 2013
- "Regulator" Information Regulator
- "Republic" Republic of South Africa
2. Purpose of PAIA Manual
This PAIA Manual is useful for the public to:
- check the categories of records held by a body which are available without a person having to submit a formal PAIA request;
- have a sufficient understanding of how to make a request for access to a record of the body, by providing a description of the subjects on which the body holds records and the categories of records held on each subject;
- know the description of the records of the body which are available in accordance with any other legislation;
- access all the relevant contact details of the Information Officer and Deputy Information Officer who will assist the public with the records they intend to access;
- know the description of the guide on how to use PAIA, as updated by the Regulator and how to obtain access to it;
- know if the body will process personal information, the purpose of processing of personal information and the description of the categories of data subjects and of the information or categories of information relating thereto;
- know the description of the categories of data subjects and of the information or categories of information relating thereto;
- know the recipients or categories of recipients to whom the personal information may be supplied;
- know if the body has planned to transfer or process personal information outside the Republic of South Africa and the recipients or categories of recipients to whom the personal information may be supplied; and
- know whether the body has appropriate security measures to ensure the confidentiality, integrity and availability of the personal information which is to be processed.
3. Key contact details for access to information of Meridian Studio (Pty) Ltd
3.1 Chief Information Officer
Name: Nicoleen Booyens
Tel: +27 61 528 0966
Email: nicoleen.booyens@meridian-architectural.com
3.2 Deputy Information Officer
Name: N/A. Tel: N/A. Email: N/A. Fax Number: N/A.
3.3 Access to information general contacts
Email: hello@meridian-architectural.com
3.4 National or Head Office
Postal Address: Still Bay, South Africa, 6674
Physical Address: Still Bay, South Africa, 6674
Telephone: +27 61 528 0966
Email: hello@meridian-architectural.com
Website: https://www.meridian-architectural.com/
4. Guide on how to use PAIA and how to obtain access to it
4.1. The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA ("Guide"), in an easily comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.
4.2. The Guide is available in English.
4.3. The aforesaid Guide contains the description of: the objects of PAIA and POPIA; the postal and street address, phone and fax number and, if available, electronic mail address of the Information Officer of every public body, and every Deputy Information Officer of every public and private body designated in terms of section 17(1) of PAIA and section 56 of POPIA; the manner and form of a request for access to a record of a public body contemplated in section 11, and access to a record of a private body contemplated in section 50; the assistance available from the IO of a public body in terms of PAIA and POPIA; the assistance available from the Regulator in terms of PAIA and POPIA; all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging an internal appeal, a complaint to the Regulator, and an application with a court against a decision by the Information Officer of a public body, a decision on internal appeal or a decision by the Regulator or a decision of the head of a private body; the provisions of sections 14 and 51 requiring a public body and private body, respectively, to compile a manual, and how to obtain access to a manual; the provisions of sections 15 and 52 providing for the voluntary disclosure of categories of records by a public body and private body, respectively; the notices issued in terms of sections 22 and 54 regarding fees to be paid in relation to requests for access; and the regulations made in terms of section 92.
4.4. Members of the public can inspect or make copies of the Guide from the offices of the public and private bodies, including the office of the Regulator, during normal working hours.
4.5. The Guide can also be obtained upon request to the Information Officer, or from the website of the Regulator (https://www.justice.gov.za/inforeg/).
4.6. A copy of the Guide is also available in English for public inspection during normal office hours.
5. Categories of records of Meridian Studio (Pty) Ltd which are available without a person having to request access
5.1. Records of a public nature, typically those disclosed on the Meridian Studio (Pty) Ltd website and in its various annual reports, may be accessed without the need to submit a formal application.
5.2. Other non-confidential records, such as statutory records maintained at CIPC, may also be accessed without the need to submit a formal application, however, please note that an appointment to view such records will still have to be made with the Information Officer.
| Category | Record | Available on Website | Available on request |
|---|---|---|---|
| Sales | Company Profile | X | X |
| Sales | Marketing Brochures | X | |
| Legislative | Tax Compliance Status Pin Letter | X | |
| Legislative | CIPC | X | |
| Sales | Sales Terms & Conditions | X |
6. Description of the records of Meridian Studio (Pty) Ltd which are available in accordance with any other legislation
6.1. Note that the accessibility of the records may be subject to the grounds of refusal set out in this PAIA manual. Amongst other, records deemed confidential on the part of a third party will necessitate permission from the third party concerned, in addition to normal requirements, before Meridian Studio (Pty) Ltd will consider access.
6.2. Where applicable to its operations Meridian Studio (Pty) Ltd also retains records and documents in terms of the legislation above. Unless disclosure is prohibited in terms of legislation, regulations, contractual agreement or otherwise, records that are required to be made available in terms of these acts shall be made available for inspection by interested parties in terms of the requirements and conditions of the Act, the above-mentioned legislation and applicable internal policies and procedures, should such interested parties be entitled to such information. A request for access must be made in accordance with the prescriptions of the Act.
| Category of Record | Applicable Legislation |
|---|---|
| MOI | Companies Act 71 of 2008 |
| Share Registers and certificates | Companies Act 71 of 2008 |
| B-BBEE Documentation | Companies Act 71 of 2008 |
| Minutes of board of directors and shareholder meetings | Companies Act 71 of 2008 |
| Proxy Forms | Companies Act 71 of 2008 |
| Records of directors, the secretary, and other officers | Companies Act 71 of 2008 |
| Annual Financial Reports and Statements | Financial and Tax Records (SARS) |
| Accounting and general ledger records | Financial and Tax Records (SARS) |
| Tax returns and supporting documents | Financial and Tax Records (SARS) |
| Workman's Compensation | Financial and Tax Records (SARS) |
| Bank statements and asset registers | Financial and Tax Records (SARS) |
| Debtors / Creditors Invoices and statements | Financial and Tax Records (SARS) |
| Rental Agreements | Financial and Tax Records (SARS) |
| Policies and Procedures | Financial and Tax Records (SARS) |
| Intellectual Property | Other Sector-Specific Records |
| Marketing Material | Other Sector-Specific Records |
6.3 Grounds for refusal of access and protection of information
There are various grounds upon which a request for access to a record may be refused. These grounds include:
- the protection of personal information of a third person (who is a natural person) from unreasonable disclosure;
- the protection of commercial information of a third party (for example: trade secrets; financial, commercial, scientific, or technical information that may harm the commercial or financial interests of a third party);
- if disclosure would result in the breach of a duty of confidence owed to a third party;
- if disclosure would jeopardize the safety of an individual or prejudice or impair certain property rights of a third person;
- if the record was produced during legal proceedings, unless that legal privilege has been waived;
- if the record contains trade secrets, financial or sensitive information or any information that would put Meridian Studio (Pty) Ltd at a disadvantage in negotiations or prejudice it in commercial competition; and/or
- if the record contains information about research being carried out or about to be carried out on behalf of a third party or by Meridian Studio (Pty) Ltd.
Section 70 of PAIA contains an overriding provision. Disclosure of a record is compulsory if it would reveal (i) a substantial contravention of, or failure to comply with the law; or (ii) there is an imminent and serious public safety or environmental risk; and (iii) the public interest in the disclosure of the record in question clearly outweighs the harm contemplated by its disclosure.
If the request for access to information affects a third party, then such third party must first be informed within 21 (twenty-one) days of receipt of the request. The third party would then have a further 21 (twenty-one) days to make representations and/or submissions regarding the granting of access to the record.
6.4 Remedies available to a requester on refusal of access
If the Information Officer decides to grant you access to the particular record, such access must be granted within 30 (thirty) days of being informed of the decision.
There is no internal appeal procedure that may be followed after a request to access information has been refused. The decision made by the Information Officer is final. In the event that you are not satisfied with the outcome of the request, you are entitled to apply to the Information Regulator or a court of competent jurisdiction to take the matter further.
Where a third party is affected by the request for access and the Information Officer has decided to grant you access to the record, the third party has 30 (thirty) days in which to appeal the decision in a court of competent jurisdiction. If no appeal has been lodged by the third party within 30 (thirty) days, you must be granted access to the record.
7. Processing of personal information
7.1 Purpose of processing personal information
In terms of POPIA, personal information must be processed for a specified purpose. The purpose for which personal information is processed by the Company will depend on the nature of the personal information and the particular data subject.
Human Resources & Employment: Managing staff administration, recruitment, payroll, performance, and legal compliance.
Customer & Client Management: Fulfilling contracts, managing client records, responding to inquiries, and providing requested products or services.
Suppliers & Service Providers: Procuring goods and services, and managing contractor/supplier relationships.
7.2 Description of the categories of data subjects and of the information or categories of information relating thereto
| Categories of Data Subjects | Personal Information that may be processed |
|---|---|
| Customers / Clients | Name, Address, Registration numbers or identity numbers, VAT number |
| Service Providers | Name, Address, Registration numbers or identity numbers, VAT number, drawings, bank details |
| Employees | Address, Identity numbers, qualifications, gender and race |
7.3 The recipients or categories of recipients to whom the personal information may be supplied
| Category of Personal Information | Recipients or Categories of Recipients to whom the personal information may be supplied |
|---|---|
| Identity number and names, for criminal checks | South African Police Services |
| Qualifications, for qualification verification | South African Qualifications Authority |
| Credit and payment history, for credit information | Credit Bureaus |
7.4 Planned transborder flows of personal information
Meridian Studio (Pty) Ltd performs transborder flows of information, only where necessary and for any lawful purpose. Meridian Studio (Pty) Ltd will ensure that anyone to whom it passes personal information is subject to a law, binding corporate rules or binding agreement which provides an adequate level of protection, and the third party agrees to treat that personal information with the same level of protection as Meridian Studio (Pty) Ltd is obliged under POPIA.
We transfer personal information abroad as follows:
- Some personal information stored on the cloud via Zoho: Data is transferred to Zoho Corporation and its affiliate entities via the Zoho platform (including Zoho Mail and Zoho WorkDrive). Zoho maintains multiple international data centres and, depending on the account region selected, data may be hosted or processed in India, the United States of America (USA), the European Union (EU), and other global regions where Zoho maintains data centres.
- Payment processing via Wise: Personal information necessary to process client and supplier payments (such as names, banking details, and transaction records) is transferred to Wise Payments Limited and its group entities via the Wise platform. Wise's main processing centres are located in the United Kingdom and the European Union, and data may also be transferred to, or stored in, other jurisdictions where Wise or its sub-processors operate.
- Website hosting and enquiry handling via Railway and Resend: The Company's website, meridian-architectural.com, and its backend run on Railway, a hosting platform with infrastructure in the United States of America (USA). Personal information submitted through the website contact form (name, firm name, email address, project type, software used, and message content) is processed and stored on Railway infrastructure, and contact form notifications and transactional email are delivered through Resend, which also processes data in the USA.
- Enquiry alerts via CallMeBot: When a new website enquiry arrives, an alert containing basic enquiry details is sent to the Company on WhatsApp via CallMeBot, which may process that data outside the Republic.
- Domain registration via GoDaddy: The Company's domain is registered through GoDaddy, a registrar based in the United States of America (USA), which processes the administrative registration data associated with the domain.
Safeguards, legal justifications, and compliance
In accordance with Section 72 of the Protection of Personal Information Act (POPIA), the Company ensures that all transborder data transfers are legally compliant through the following mechanisms:
- Contractual Commitments: The Company has entered into the mandatory Zoho Data Processing Addendum (DPA). This agreement legally binds Zoho to process personal data strictly on our instructions and to maintain stringent privacy protections that align with POPIA expectations.
- Adequate Level of Protection: The data is transferred to jurisdictions or entities bound by framework principles (such as the EU GDPR) that offer an adequate level of data protection substantially similar to POPIA.
- Technical Security Safeguards: All personal data transferred to Zoho services is secured using enterprise-grade technical measures, including data encryption in transit (using HTTPS/TLS) and encryption at rest.
- Wise Contractual Commitments: Where the UK or EU GDPR applies to a transfer, Wise enters into the EU Standard Contractual Clauses approved by the European Commission and/or the UK International Data Transfer Addendum issued by the Information Commissioner's Office with the relevant data importer, and holds its sub-processors, including data centre partners, to equivalent data management, security, and privacy standards.
- Wise Technical Security Safeguards: Payment data transferred to Wise is protected using industry-standard technical measures, including encryption in transit and at rest, consistent with Wise's regulatory obligations as an authorised payment institution.
- Website Infrastructure Safeguards: Transfers to Railway, Resend, CallMeBot, and GoDaddy take place under those providers' contractual data protection commitments and established security programmes. The website is served over encrypted connections (HTTPS/TLS), access to enquiry records is restricted to authorised personnel via magic-link authentication, and these providers process personal information only as needed to deliver their service to the Company, as further described in the Company's Privacy Policy.
7.5 General description of information security measures
The Company takes extensive information security measures to ensure the confidentiality, integrity and availability of personal information in our possession. The Company takes appropriate technical and organisational measures designed to ensure that personal information remains confidential and secure against unauthorised or unlawful processing and against accidental loss, destruction or damage.
8. Availability of the Manual
8.1. A copy of the Manual is available on https://www.meridian-architectural.com/, at the head office of Meridian Studio (Pty) Ltd for public inspection during normal business hours, to any person upon request and upon the payment of a reasonable prescribed fee, and to the Information Regulator upon request.
8.2. A fee of ZAR140 for a copy of the Manual, as contemplated in Annexure B of the Regulations, shall be payable per each A4-size photocopy made.
9. Updating of the Manual
The head of Meridian Studio (Pty) Ltd will on a regular basis update this manual.
Issued by Nicoleen Booyens, Chief Information Officer.

