SPF Finances API Compliance Statement

Entity: Belgium Accounting (Fontaine Farm BV)
BCE/KBO: 1004.190.223
Last Updated: October 15, 2025
Version: 1.0

Overview

This document outlines Belgium Accounting's compliance with the SPF Finances (Belgian Federal Public Service for Finance) User Convention for API access to MyMinFin and Intervat services. We are committed to maintaining the highest standards of security, transparency, and regulatory compliance in our integration with Belgian government financial services.

What is an API?

API stands for Application Programming Interface. It's a secure way for different software applications to communicate with each other automatically, without requiring manual data entry.

Example: Instead of manually downloading your tax documents from MyMinfin and uploading them to Belgium Accounting, our API connection automatically retrieves them securely in the background, saving you time and reducing errors.

Security: API connections use encrypted channels and require your explicit authorization through OAuth (like "Sign in with Google"). You can revoke access at any time.

Article 6.3: User Information Requirements

COMPLIANCE STATUS: ✓ FULLY COMPLIANT

1. SPF User Convention Disclosure

A formal User Convention exists between Belgium Accounting (Fontaine Farm BV, BCE 1004.190.223) and SPF Finances Belgium. This convention governs API access, security requirements, data handling, and compliance obligations. Users may request a copy of this convention by contacting support@contabilite.space.

2. No Direct SPF Support

⚠️ IMPORTANT NOTICE

SPF Finances provides NO direct technical support to end users of Belgium Accounting. All support requests must be directed to our support team at support@contabilite.space. SPF Finances will not respond to support requests from individual users of third-party applications.

3. First-Line Support Responsibility

Belgium Accounting provides comprehensive first-line technical support for all SPF Finances integration features, including OAuth authentication, MyMinFin document access, and Intervat VAT return submission. Our support team is available via email at support@contabilite.space.

4. Reporting Compromised Access

If you suspect your SPF Finances access credentials have been compromised:

  1. Immediately contact our support team: support@contabilite.space
  2. We will revoke OAuth access tokens within 1 hour
  3. Change your MyMinfin password via SPF's official portal
  4. Re-authorize access through our secure OAuth flow

5. SPF Finances Rights

SPF Finances Belgium retains the following rights:

Article 6.4: Marketing Compliance

COMPLIANCE STATUS: ✓ FULLY COMPLIANT

Marketing Restrictions Adherence

Belgium Accounting strictly adheres to SPF Finances marketing guidelines:

Restriction Status Implementation
No SPF Finances logo usage Compliant No SPF logos on website or marketing materials
No "approved" or "certified" claims Compliant No false endorsement claims
No "official partner" designation Compliant Clear technical integration relationship only
Only approved text usage Compliant "Compatible with MyMinfin of SPF Finances" only

Approved Marketing Text:

"Compatible with MyMinfin of SPF Finances"

This text appears in the footer of all pages in French, Dutch, English, and German.

Article 9.3: Audit Trail Requirements

COMPLIANCE STATUS: ✓ FULLY COMPLIANT

Comprehensive Audit Logging

Belgium Accounting logs all authentications, authentication attempts, and API transactions with SPF Finances services as required by Article 9.3.

Data Captured in Audit Logs:

Retention & Retrieval:

Audit Log Availability:

Audit logs are available to SPF Finances Belgium upon request for compliance verification, security audits, or incident investigation. Requests should be sent to support@contabilite.space with appropriate authorization.

Article 12: Security & Incident Response

COMPLIANCE STATUS: ✓ FULLY COMPLIANT

Security Measures Implemented:

Incident Response Procedures:

Data Breach (GDPR Article 33):

  1. Detection & assessment within 24 hours
  2. Notification to Belgian Data Protection Authority within 72 hours
  3. User notification if high risk to rights and freedoms
  4. Documentation of breach, response, and mitigation
  5. Contact: https://www.autoriteprotectiondonnees.be/

Cybersecurity Incident:

  1. Follow FEB (Federation of Belgian Enterprises) Cyber Incident Roadmap
  2. Immediate containment and isolation of affected systems
  3. Forensic analysis and evidence preservation
  4. Notification to SPF Finances if API access compromised
  5. Post-incident review and security enhancement
  6. Reference: https://www.vbo-feb.be/fr/publications/cyber-incident-roadmap/

API Usage & Rate Limits

Belgium Accounting adheres to SPF Finances API rate limits:

Service Endpoint Rate Limit Enforcement
MyMinFin API /documents (search) 1 request per 10 minutes per company Application-level rate limiting + 429 response handling
MyMinFin API /documents/{id} (download) 12 requests per minute per company Application-level rate limiting + 429 response handling
Intervat API /vat-return (submit) No published limit (reasonable use) Monitoring and throttling if needed

429 Response Handling: When SPF Finances APIs return HTTP 429 (Too Many Requests), our system automatically respects the Retry-After header and queues subsequent requests appropriately.

Contact Information

Belgium Accounting:

SPF Finances Resources:

Compliance Verification

SPF Finances Belgium may verify our compliance with the User Convention at any time. We welcome audits and compliance reviews. To request access to audit logs, security documentation, or schedule a compliance review, please contact support@contabilite.space with appropriate authorization.

Our Commitment: Belgium Accounting is committed to maintaining full compliance with all SPF Finances requirements, protecting user data, and providing transparent, secure access to Belgian government financial services.