# POL-022 — The policy must be the brand's own, not a platform's

> A reseller's, platform's, ISV's or generic vendor privacy policy must not be submitted in place of the brand's own.

- **Rule ID:** POL-022
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body (authorship)`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** Telnyx, Twilio, Bandwidth
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-022/

## Why this rule exists

The policy is a promise by the business that collected the number, and a platform's policy promises nothing on the brand's behalf — so the consumer has no commitment from anyone they actually deal with. Telnyx names the specific version of this it sees most: Google's policy submitted as the brand's, because the business runs on Google services and assumed that covered it.

## How to fix it

Publish a policy in the brand's own name covering the brand's own data handling, and link the platform's policy separately if you want to. Done when the document names the registered business as the party making the promises.

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Bandwidth | `7102` | yes |

## Notes

About authorship, and distinct from POL-021, which is about where the document is hosted. A brand-authored policy hosted on a vendor domain passes this and fails that; a vendor-authored policy on the brand's own domain does the reverse.
