# POL-129 — The policy must name or categorise its processors

> The privacy policy must name or categorise the third-party processors that handle personal information.

- **Rule ID:** POL-129
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** TCR
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-129/

## Why this rule exists

The service-provider carve-back the messaging clause depends on is only meaningful if the reader can tell who the service providers are — otherwise "vendors acting on our behalf" is an open door with a friendly label. Naming the messaging platform and the carriers is also the sentence that makes the carve-back obviously narrow rather than obviously convenient.

## How to fix it

List the processor categories, naming the messaging vendor explicitly. Done when the carve-back in the messaging clause points at a list a reader can actually see.

## Example of a compliant value

```text
Our processors are: our messaging platform and the wireless carriers that deliver the texts, our hosting provider, our payment processor, and our analytics provider.
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Bandwidth/DCA | `7109` | yes |
