# POL-065 — Boilerplate "trusted partners" language must be removed or narrowed

> Generic policy-generator output such as "we may share with trusted partners" must be removed or narrowed to service providers.

- **Rule ID:** POL-065
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** TCR, Twilio, AWS
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-065/

## Why this rule exists

Ranked #4 most-missed. Free privacy-policy generators emit permissive sharing language by default, and the business pasting it in has no idea it contradicts their messaging programme. It is the most common source of the inverse trap because nobody wrote the sentence deliberately.

## How to fix it

Replace vague partner language with a specific, closed list of processor categories, and state that messaging data is excluded from all of them.

## Example of a compliant value

```text
We share personal information only with service providers who perform functions on our behalf (payment processing, order fulfilment, and message delivery). We do not share personal information with third parties for their own marketing purposes.
```
