# POL-095 — The policy must say how to contact the sender

> The privacy policy must describe how consumers can contact the sender about their information.

- **Rule ID:** POL-095
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** Bandwidth, Sakari, MessageDesk
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-095/

## Why this rule exists

Every right the policy grants — access, deletion, opting out — depends on there being someone to ask, so a document with no contact route grants nothing it can deliver. The address is also what a reviewer uses to corroborate the brand, which is why a bare web form fails where an email address on the brand domain passes.

## How to fix it

Add a privacy contact block with an email address on the brand domain and the business postal address. Done when a reader can write to a person without using a form.

## Example of a compliant value

```text
Privacy questions: privacy@acmecoffee.com, or Acme Coffee Co, LLC, 1240 Mission St, Suite 400, San Francisco, CA 94103.
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Bandwidth | `7102` | yes |
