{
  "id": "POL-022",
  "slug": "pol-022",
  "title": "The policy must be the brand's own, not a platform's",
  "statement": "A reseller's, platform's, ISV's or generic vendor privacy policy must not be submitted in place of the brand's own.",
  "rationale": "The policy is a promise by the business that collected the number, and a platform's policy promises nothing on the brand's behalf — so the consumer has no commitment from anyone they actually deal with. Telnyx names the specific version of this it sees most: Google's policy submitted as the brand's, because the business runs on Google services and assumed that covered it.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body (authorship)",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "Telnyx",
    "Twilio",
    "Bandwidth"
  ],
  "codes": [
    {
      "provider": "Bandwidth",
      "code": "7102",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Publish a policy in the brand's own name covering the brand's own data handling, and link the platform's policy separately if you want to. Done when the document names the registered business as the party making the promises.",
  "notes": "About authorship, and distinct from POL-021, which is about where the document is hosted. A brand-authored policy hosted on a vendor domain passes this and fails that; a vendor-authored policy on the brand's own domain does the reverse.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-022/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-022.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
