# POL-041 — Offline and keyword opt-in copy must carry the route to the policy

> Verbal, IVR, keyword and email opt-in copy must state where the privacy policy can be found, or carry the disclosures inline.

- **Rule ID:** POL-041
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `verbal script, IVR prompt, keyword CTA or opt-in email body`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Produce a document that does not exist yet
- **Required by:** Bandwidth, AWS
- **Applies:** Applies when consent was collected by live verbal, IVR, text-to-join keyword and email.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-041/

## Why this rule exists

None of these surfaces has a link: a caller cannot click, and a keyword instruction on a poster is read rather than tapped. So the route has to be spoken or printed — a typeable address — or the disclosures have to be said out loud, and a script that mentions neither collects consent from someone who was never told where the terms are.

## How to fix it

Add one sentence to the script or the opt-in copy naming where the terms and privacy policy live, spoken as a typeable address. Done when someone who only heard or read the opt-in knows where to find the policy.

## Common mistakes

- Naming the policy in the confirmation text is too late — the consumer has already consented. It has to be in the copy that asks.

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Bandwidth/DCA | `7107` | yes |

## Notes

Absorbs POL-042, which states the same requirement for keyword and email opt-in. A spoken or printed reference does not substitute for a compliant page: the policy it points at still has to satisfy the rest of this layer.
