EGT
  • Platform
    Explore the entire platformThe whole platform, in one place — click through for the full picture.

    Discover Platform Features

    SiteA presence you own — pages, profiles, and media, brand-aware and fast.MarketplaceDigital goods, physical subscriptions, and more — one universal checkout.ReachThe message lives beside the relationship — newsletters from the same customer graph.EngageLoyalty your customers won't resent — opt-in, honest, never a nag.AppArtisanExtend, develop, design, deploy — reviewed plugins that grow what you can do.WorkflowsWhen something happens, the follow-up runs itself.IntrepidYour AI partner, working while you sleep.CompareThe whole stack, side by side — every capability in one view.
  • Intrepid
  • Forge
  • Voice
  • Entertainment
  • Exploit
  • Join the Beta
  • Platform
    Explore the entire platformThe whole platform, in one place — click through for the full picture.

    Discover Platform Features

    SiteA presence you own — pages, profiles, and media, brand-aware and fast.MarketplaceDigital goods, physical subscriptions, and more — one universal checkout.ReachThe message lives beside the relationship — newsletters from the same customer graph.EngageLoyalty your customers won't resent — opt-in, honest, never a nag.AppArtisanExtend, develop, design, deploy — reviewed plugins that grow what you can do.WorkflowsWhen something happens, the follow-up runs itself.IntrepidYour AI partner, working while you sleep.CompareThe whole stack, side by side — every capability in one view.
    Intrepid
    Forge
    Voice
    Entertainment
    Exploit
Skip to the document

Legal

Business Associate Agreement

HIPAA Business Associate Agreement · Version 3 · Effective as to a Covered Entity on the date it is accepted

Contents+
1. Purpose and Scope2. Definitions3. Permitted Uses and Disclosures4. Safeguards and Security5. Reporting and Cooperation5A. Individual Rights and HHS Access6. Covered Entity Responsibilities7. Retention, Return, and Destruction8. Term and Termination9. Limitation of Liability and Indemnification10. Independent Contractor; No Agency11. Amendments and Updates12. MiscellaneousAcceptanceSchedule A — Particulars

Contents

1. Purpose and Scope2. Definitions3. Permitted Uses and Disclosures4. Safeguards and Security5. Reporting and Cooperation5A. Individual Rights and HHS Access6. Covered Entity Responsibilities7. Retention, Return, and Destruction8. Term and Termination9. Limitation of Liability and Indemnification10. Independent Contractor; No Agency11. Amendments and Updates12. MiscellaneousAcceptanceSchedule A — Particulars

Version 3

Effective Date: This Agreement is effective as to a given Covered Entity on the date that Covered Entity accepts it (the "Effective Date"), as described below.

Incorporation by reference. This Agreement is incorporated by reference into Part 11 (HIPAA) of The EGT Codex and supplements the Parties' Underlying Agreement.

This Business Associate Agreement ("Agreement" or "BAA") is entered into by and between:

Covered Entity — the tenant (person or entity) that accepts this Agreement during onboarding, identified by the account and the authorized representative who accepts it, and

The EGT Universe, LLC, an Ohio limited liability company doing business as EGT ("Business Associate," "The Universe," "we," or "us").

Covered Entity and Business Associate are each a "Party" and collectively the "Parties." This Agreement is effective as of the earlier of the Effective Date of the Parties' underlying service agreement or the date Covered Entity accepts this Agreement electronically during onboarding.

Electronic acceptance. This Agreement is presented and accepted electronically (clickwrap) during onboarding; no handwritten or countersigned signature is required from either Party. By accepting, the individual accepting represents that they are authorized to bind Covered Entity and consents to transacting electronically. The platform records the accepting account, identity, the exact document version and content hash, the timestamp, and the originating IP/user-agent as the record of acceptance.

1. Purpose and Scope

1.1 Purpose. Covered Entity has engaged Business Associate to provide access to a multi-purpose software platform known as The Universe. Certain applications, services, or environments within The Universe may be configured to process Protected Health Information ("PHI") on behalf of Covered Entity. This Agreement governs Business Associate's handling of PHI solely as required by HIPAA and applicable law.

1.2 Designated PHI Environment. HIPAA obligations under this Agreement apply only to PHI processed within infrastructure, databases, servers, applications, and workflows that are expressly designated by Business Associate as Designated PHI Environments. All other components of The Universe are non-PHI systems and are not subject to this Agreement.

1.3 Capacity Limitation. Business Associate acts as a Business Associate solely when operating within a Designated PHI Environment. Business Associate does not act as a business associate with respect to data processed outside such environments unless Business Associate has actual knowledge, or in the exercise of reasonable diligence should have known, that such data constitutes PHI.

1.4 PHI Hosting and No AI Training. For Covered Entities that opt in to HIPAA-enabled services, PHI within Designated PHI Environments is hosted in a secure environment designated for that purpose, under a HIPAA-compliant arrangement, with any cloud or hosting subcontractor that creates, receives, maintains, or transmits PHI bound by a business associate agreement. Business Associate will not use, and will not permit any subcontractor to use, PHI to train, fine-tune, or otherwise develop artificial-intelligence or machine-learning models.

2. Definitions

Capitalized terms not defined herein have the meanings set forth in HIPAA (45 C.F.R. Parts 160 and 164) or in The EGT Codex (Terms of Service & Privacy Policy), in the Version in effect when Covered Entity accepts this Agreement, available at https://egt.studio/legal.

  • "PHI" means Protected Health Information as defined in 45 C.F.R. §160.103.
  • "ePHI" means PHI in electronic form.
  • "Designated PHI" means PHI that Covered Entity has properly identified, classified, and configured to be processed within a Designated PHI Environment.
  • "Designated PHI Environment" means servers, databases, storage, and applications expressly identified by Business Associate as PHI-enabled and isolated from non-PHI systems.
  • "Designated Record Set" has the meaning set forth in 45 C.F.R. §164.501.

3. Permitted Uses and Disclosures

3.1 Service Delivery; Minimum Necessary. Business Associate may use and disclose PHI solely to provide the services requested by Covered Entity within a Designated PHI Environment. Business Associate will limit its uses, disclosures, and requests of PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. §164.502(b).

3.2 Management and Legal Obligations. Business Associate may use PHI for its internal management, administration, and legal responsibilities as permitted by 45 C.F.R. §164.504(e)(4).

3.3 De-Identification. Business Associate may de-identify PHI in compliance with 45 C.F.R. §164.514 and may use or disclose de-identified or aggregated data for analytics, research, platform improvement, and service development.

3.4 No Independent Marketing. Business Associate will not use PHI for independent marketing or advertising to individuals.

3.5 Universe Account Information (Non-PHI). The Parties acknowledge that Universe Accounts are general-purpose user accounts used across The Universe platform and are not created solely for health-related services. Information collected, generated, or maintained in connection with a Universe Account — including but not limited to account identifiers, usernames, authentication credentials, contact information, security settings, billing information, usage metadata, and account-level preferences ("Universe Account Information") — is not considered PHI for purposes of this Agreement unless and until such information is combined with or explicitly designated as PHI within a Designated PHI Environment. Accordingly:

(a) Universe Account Information is excluded from the scope of this Agreement and is governed by The EGT Codex, not this Agreement;

(b) Business Associate may use Universe Account Information for general platform operations, security, analytics, billing, customer support, product development, and other lawful business purposes consistent with The EGT Codex;

(c) The creation or use of a Universe Account, by itself, does not establish a business associate relationship or cause all information associated with that account to be treated as PHI; and

(d) If Covered Entity configures an application or workflow such that Universe Account Information is intentionally incorporated into a Designated PHI Environment or otherwise used to identify an individual in connection with PHI, then such information will be treated as PHI only within that context and subject to this Agreement and applicable law.

Nothing in this Section limits Business Associate's obligations with respect to information that meets the definition of PHI under HIPAA and is processed within a Designated PHI Environment.

4. Safeguards and Security

4.1 Administrative, Technical, and Physical Safeguards. Business Associate will implement reasonable and appropriate administrative, technical, and physical safeguards consistent with the HIPAA Security Rule (45 C.F.R. §§164.308–164.316) to protect ePHI within Designated PHI Environments, including encryption of ePHI at rest and in transit, unique user identification, access controls, and audit controls.

4.2 Designated Security Official. Business Associate maintains a designated security official — its "Security" function — who is responsible for developing and implementing Business Associate's security policies and procedures with respect to ePHI, as contemplated by 45 C.F.R. §164.308(a)(2). The role of the Company's Security function is set forth in Schedule A.

4.3 Segregation of Systems. PHI will be processed only within designated servers and databases logically and operationally segregated from non-PHI infrastructure.

4.4 Subcontractors. In accordance with 45 C.F.R. §§164.502(e)(1)(ii) and 164.308(b), Business Associate will require, by written agreement, that any subcontractor that creates, receives, maintains, or transmits PHI within Designated PHI Environments on Business Associate's behalf agrees to restrictions, conditions, and safeguards on PHI that are at least as protective as those that apply to Business Associate under this Agreement.

5. Reporting and Cooperation

5.1 Breaches and Security Incidents. Business Associate will notify Covered Entity of any Breach of Unsecured PHI within a Designated PHI Environment without unreasonable delay and in no event later than thirty (30) calendar days after discovery, consistent with 45 C.F.R. §164.410. Separately, Business Associate reports Security Incidents affecting PHI within a Designated PHI Environment as required by 45 C.F.R. §164.314(a)(2)(i)(C); a Security Incident that involves the unauthorized access, use, disclosure, modification, or destruction of PHI is reported on the same thirty (30) calendar-day timeline, and routine unsuccessful events are reported, if at all, on an aggregate basis under Section 5.2. For purposes of this Section, a Breach or Security Incident is "discovered" on the first day it is known to Business Associate, or by exercising reasonable diligence would have been known to Business Associate, consistent with 45 C.F.R. §164.410(a)(2). Where applicable state law requires a shorter notification period, Business Associate will reasonably cooperate to enable Covered Entity's timely compliance.

5.2 Routine Activity. Routine unsuccessful security events (e.g., failed logins, scans, pings) do not require individual notice and are reported, if at all, on an aggregate basis.

5.3 Covered Entity Reporting. Covered Entity will notify Business Associate of any Breach of Covered Entity's own systems that may affect the Designated PHI Environment without unreasonable delay and in no event later than thirty (30) calendar days after discovery.

5A. Individual Rights and HHS Access

To the extent Business Associate maintains PHI in a Designated Record Set within a Designated PHI Environment, Business Associate will, within commercially reasonable timeframes and using the tools the platform provides:

(a) make PHI available to Covered Entity as necessary to satisfy Covered Entity's obligations with respect to an individual's right of access under 45 C.F.R. §164.524;

(b) make PHI available for amendment, and incorporate any amendment to PHI, as directed by Covered Entity pursuant to 45 C.F.R. §164.526;

(c) maintain and make available the information required to provide an accounting of disclosures so that Covered Entity may meet its obligations under 45 C.F.R. §164.528; and

(d) make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's and Business Associate's compliance with HIPAA, in accordance with 45 C.F.R. §164.504(e)(2)(ii)(I).

Any request that an individual makes directly to Business Associate for access to, amendment of, or an accounting of disclosures of PHI will be forwarded to Covered Entity, which is responsible for responding to such request.

6. Covered Entity Responsibilities

6.1 Compliance. Covered Entity is solely responsible for its compliance with HIPAA, 42 C.F.R. Part 2 (if applicable), and state law, including applicable medical-record retention and state breach-notification statutes.

6.2 PHI Identification and Configuration. Covered Entity must properly designate, classify, and configure all PHI to be processed within a Designated PHI Environment, including affirmatively opting in to HIPAA-enabled services and marking PHI using the tools the platform provides.

6.3 Misclassification. Business Associate may rely on Covered Entity's classification of data. Business Associate bears no liability for PHI processed outside Designated PHI Environments unless it had actual knowledge, or in the exercise of reasonable diligence should have known, that such data was PHI.

7. Retention, Return, and Destruction

7.1 No Long-Term Retention; Return or Destroy. Business Associate does not retain PHI longer than necessary to provide the services. Upon termination, expiration, or Covered Entity's request, Business Associate will, at Covered Entity's election and where feasible, return and/or destroy PHI within the Designated PHI Environment. Business Associate is not required to retain PHI after the services end; the long-term retention of records to satisfy HIPAA, state medical-record retention law, or other law is the responsibility of Covered Entity as the covered entity. If return or destruction of PHI is infeasible, Business Associate will extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible, for so long as Business Associate maintains such PHI, consistent with 45 C.F.R. §164.504(e)(2)(ii)(I).

7.2 Data Grace Period. Following non-payment, cancellation, or termination, Business Associate provides a data-grace period of thirty (30) days during which active service may be suspended but Covered Entity's data remains retrievable so that Covered Entity may renew and retrieve its data. Business Associate will not withhold a Covered Entity's PHI as leverage over a billing dispute. After the grace period, PHI is securely destroyed under Section 7.3.

7.3 Secure Destruction (Cryptographic Erasure). PHI is encrypted with per-tenant keys. Destruction is performed by cryptographic erasure — destroying the tenant's encryption keys renders the corresponding PHI permanently inaccessible, including in backups — followed by record deletion and backup expiry, and, on request, a certificate of destruction. This Section supersedes any prior statement that destruction could not be guaranteed due to backups.

7.4 Optional Archival. Covered Entity may elect, in writing and for an additional fee, a HIPAA-compliant archival of its PHI within a Designated PHI Environment beyond the standard period. Absent such election, Sections 7.1–7.3 control.

8. Term and Termination

This Agreement remains in effect until all PHI is returned and/or destroyed or rendered inaccessible in accordance with Section 7, or, where return or destruction is infeasible, for so long as Business Associate maintains such PHI subject to the protections extended under Section 7.1.

9. Limitation of Liability and Indemnification

9.1 Relationship to The EGT Codex. This Agreement incorporates by reference the limitation of liability, disclaimers of warranty, and damages exclusions set forth in The EGT Codex (the Company's Terms of Service & Privacy Policy) located at https://egt.studio/legal (the "Codex"). To the maximum extent permitted by applicable law, those Codex limitations apply fully to this Agreement and to any claim arising out of or related to PHI, HIPAA, 42 C.F.R. Part 2, or this Agreement, except as expressly modified below. In the event of a conflict between the Codex and this Agreement with respect to PHI, this Agreement controls; the Parties intend that no claim relating to PHI is left without an applicable limitation of liability. A single claim, or a single incident giving rise to a claim, that includes both a PHI component and a non-PHI component is governed in its entirety by the cap in Section 9.2, and not in part by any limitation in the Codex; there are not two competing caps for such a mixed claim, and the cap in Section 9.2 is the single, controlling limitation for the whole of it, except for liability that may not be limited under Section 9.2(d).

9.2 Limitation of Liability. TO THE MAXIMUM EXTENT PERMITTED BY LAW:

(a) Exclusion of Certain Damages. UNDER NO CIRCUMSTANCE WILL BUSINESS ASSOCIATE OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, PUNITIVE, OR OTHER DAMAGES, INCLUDING WITHOUT LIMITATION LOST PROFITS, LOSS OF REVENUE, LOSS OF BUSINESS, OR LOSS OF INFORMATION OR DATA, ARISING OUT OF OR RELATED TO THIS AGREEMENT OR THE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

(b) Aggregate Liability Cap. EXCEPT AS PROVIDED IN SECTION 9.2(d), THE TOTAL AGGREGATE LIABILITY OF BUSINESS ASSOCIATE ARISING OUT OF OR RELATING TO THIS AGREEMENT — INCLUDING ANY USE, DISCLOSURE, SECURITY INCIDENT, OR BREACH OF PHI — WILL NOT EXCEED THE GREATER OF (i) THE TOTAL FEES ACTUALLY PAID BY COVERED ENTITY TO BUSINESS ASSOCIATE FOR THE SERVICES DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (ii) A FLOOR OF TWO THOUSAND FIVE HUNDRED U.S. DOLLARS ($2,500); SUBJECT IN ALL CASES TO AN ABSOLUTE MAXIMUM OF FIFTY THOUSAND U.S. DOLLARS ($50,000). FOR ANY CLAIM ARISING OUT OF OR RELATING TO PHI, THE LIMITS IN THIS SECTION 9.2 — AND NOT ANY LIMITATION IN THE EGT CODEX — ARE THE SOLE AND CONTROLLING LIMITATION OF LIABILITY AND SUPERSEDE ANY LOWER OR HIGHER CAP IN THE EGT CODEX. THIS SECTION 9.2(b) CONTROLS ONLY THE CAPPED PHI CLAIMS; IT DOES NOT LIMIT THE LIABILITY EXCEPTED FROM THE CAP UNDER SECTION 9.2(d), WHICH REMAINS UNCAPPED FOR PHI CLAIMS AS FOR ALL OTHERS.

(c) Breach of Unsecured PHI. EXCEPT AS PROVIDED IN SECTION 9.2(d), CLAIMS ARISING FROM A BREACH OF UNSECURED PHI, OR FROM BREACH OF BUSINESS ASSOCIATE'S CONFIDENTIALITY OR SAFEGUARDING OBLIGATIONS UNDER SECTIONS 3, 4, AND 7, ARE SUBJECT TO THE SAME CAPS SET FORTH IN SECTION 9.2(b). THERE IS NO SEPARATE OR HIGHER LIMIT FOR SUCH CAPPED CLAIMS. NOTHING IN THIS SECTION 9.2(c) LIMITS THE LIABILITY EXCEPTED FROM THE CAP UNDER SECTION 9.2(d).

(d) Excluded (Uncapped) Claims. THE EXCLUSIONS AND CAPS IN THIS SECTION 9.2 DO NOT APPLY TO LIABILITY ARISING FROM: (i) BUSINESS ASSOCIATE'S FRAUD; (ii) BUSINESS ASSOCIATE'S WILLFUL MISCONDUCT; (iii) BUSINESS ASSOCIATE'S GROSS NEGLIGENCE; OR (iv) ANY LIABILITY THAT CANNOT BE LIMITED OR EXCLUDED UNDER APPLICABLE LAW. FOR THE AVOIDANCE OF DOUBT, AND EXCEPT TO THE EXTENT CLAUSE (iv) APPLIES, CLAIMS ARISING FROM A BREACH OF UNSECURED PHI, FROM BUSINESS ASSOCIATE'S BREACH OF ITS CONFIDENTIALITY OR SAFEGUARDING OBLIGATIONS, AND ANY INDEMNITY FOR CIVIL MONETARY PENALTIES, FINES, OR SANCTIONS IMPOSED BY HHS, THE OFFICE FOR CIVIL RIGHTS, OR A STATE ATTORNEY GENERAL ATTRIBUTABLE TO BUSINESS ASSOCIATE ARE NOT UNCAPPED AND ARE SUBJECT TO THE CAPS IN SECTIONS 9.2(b) AND 9.2(c).

(e) Controlling Figures. THE FIGURES AND LIMITS STATED IN THIS SECTION 9.2 CONTROL OVER, AND SUPERSEDE, ANY LOWER LIMITATION OF LIABILITY SET FORTH IN THE EGT CODEX OR ANY OTHER UNDERLYING AGREEMENT WITH RESPECT TO CLAIMS ARISING OUT OF OR RELATING TO PHI.

9.3 Limited Indemnification by Business Associate. Subject to Section 9.2, Business Associate will defend and indemnify Covered Entity from third-party claims only to the extent directly caused by Business Associate's gross negligence or willful misconduct in breach of this Agreement. Business Associate will not indemnify Covered Entity for claims arising from: Covered Entity's failure to comply with HIPAA, 42 C.F.R. Part 2, or other applicable law; Covered Entity's instructions, configurations, misuse, or failure to use available classification tools to designate PHI; Covered Entity's failure to obtain required consents or authorizations; PHI that Business Associate did not know and could not reasonably have known constituted PHI because Covered Entity failed to designate it properly; or Covered Entity's independent acts or omissions.

9.4 Indemnification by Covered Entity. Covered Entity will defend, indemnify, and hold harmless Business Associate from any third-party claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from or relating to: Covered Entity's misclassification or failure to designate data as PHI; Covered Entity's breach of applicable law or failure to obtain required authorizations; Covered Entity's instructions that cause Business Associate to use or disclose PHI in violation of law; or Covered Entity's breach of its obligations under this Agreement or The EGT Codex.

9.5 Regulatory Authority. Nothing in this Agreement limits the authority of the U.S. Department of Health and Human Services, state regulators, or other governmental authorities to investigate, enforce, or impose penalties under applicable law. Regulatory fines or penalties imposed directly on Covered Entity are not damages recoverable from Business Associate under this Agreement, except to the extent such penalties are directly attributable to Business Associate's own acts or omissions in breach of this Agreement, in which case any such liability is subject to the caps in Section 9.2(b) and Section 9.2(c).

9.6 Allocation of Risk. The fees charged to Covered Entity reflect the allocation of risk in this Section 9; Business Associate is not an insurer or guarantor of Covered Entity's compliance obligations; and this Section 9 survives termination.

10. Independent Contractor; No Agency

The Parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, agency, or employment relationship. Covered Entity does not direct or control the manner or means by which Business Associate performs the services, and neither Party may bind the other. The Parties do not intend for Business Associate to act as Covered Entity's agent for purposes of HIPAA or otherwise.

11. Amendments and Updates

This Agreement may be amended to comply with changes in law or Business Associate's PHI standards. The current version is published at https://egt.studio/legal/baa with a version identifier. Consistent with the change discipline in Section 1.5 of The EGT Codex, a material change to this Agreement is made on advance notice and re-acceptance; a non-material change takes effect on posting. Continued use of PHI-enabled services after notice of a non-material new version constitutes acceptance where permitted by law.

12. Miscellaneous

12.1 No Third-Party Beneficiaries. Except as expressly provided by applicable law, nothing in this Agreement confers rights or remedies on any person other than the Parties.

12.2 Governing Law. This Agreement is governed by and construed in accordance with the laws of the State of Ohio, without regard to its conflict-of-laws rules, except to the extent preempted by federal law, including HIPAA and related regulations.

12.3 Underlying Service Agreement; Order of Precedence. This Agreement supplements the Parties' underlying service agreement — which is The EGT Codex (the Company's Terms of Service & Privacy Policy) together with the applicable subscription Order, or a separate Service Agreement / Proposal where one exists (the "Underlying Agreement"). This Agreement, together with the Underlying Agreement, constitutes the entire understanding of the Parties with respect to PHI. In the event of a conflict concerning PHI, this Agreement controls; in all other respects the Underlying Agreement controls. The Parties intend no gap that would leave a PHI-related claim without an applicable limitation of liability.

12.4 Severability. If any provision is found invalid or unenforceable, it will be reformed to the minimum extent necessary to make it enforceable consistent with its original intent, and the remaining provisions remain in full force.

12.5 Entire Agreement. This Agreement, together with the Underlying Agreement, constitutes the entire understanding of the Parties with respect to PHI and supersedes all prior discussions or agreements on that subject. In case of conflict regarding PHI, this Agreement controls as stated in Section 1.2 and Section 12.3.

12.6 Electronic Acceptance and Records. This Agreement is accepted electronically; the Parties agree that electronic acceptance and electronically stored records of acceptance are valid, enforceable, and admissible to the same extent as a signed writing under applicable electronic-signature law (e.g., ESIGN/UETA).

Acceptance

By accepting this Agreement electronically during onboarding, the individual accepting represents that they (a) have read and understand this Agreement; (b) are an authorized representative of Covered Entity with authority to bind Covered Entity; (c) intend Covered Entity to be legally bound by its terms; and (d) consent to transacting and maintaining records electronically. The platform records the accepting account and identity, the exact document version and content hash, the timestamp, and the originating IP and user-agent as the binding record of acceptance. No countersignature by Business Associate is required; Business Associate's provision of the Designated PHI Environment constitutes its acceptance.


Schedule A — Particulars

The following items are supplied by Business Associate. Each is a controlled particular, not a negotiated term.

  • Business Associate legal name: The EGT Universe, LLC (an Ohio limited liability company).
  • HIPAA notice / breach contact: Reachable through the Security contact stated in The EGT Codex (the security intake form and security@egt.studio), which routes to the Company's dashboard workflow. Urgent breach communications are made through that Security contact.
  • Notice address (formal legal notice only): c/o Incorp Services, Inc. (registered agent), 9435 Waterstone Boulevard, Suite 140, Cincinnati, OH 45249. This is the Business Associate's registered-agent commercial address for formal legal notice. Routine and breach notices are made by email / web form as stated above.
  • Designated Security Official: Security, The EGT Universe, LLC (the Company's security function, as designated under 45 C.F.R. §164.308(a)(2)).
  • Authorized signatory: Accepted electronically by The EGT Universe, LLC through its authorized systems upon the Covered Entity's acceptance.
EGT

EGT — A house of studios — building the Universe.

The Studios

  • The Universe Platform by EGTUnify everything.
  • IntrepidAI partner working while you sleep.
  • ForgeCreative agency
  • VoiceOn-device voice creation
  • EntertainmentMusic & the book
  • ExploitBook One of The Universe

Company

  • About
  • Join the beta

Connect

  • Contact
  • Instagram
  • YouTube

Legal

  • The Universe CodexIncluding the Terms of Service & Privacy Policy
  • Business Associate Agreement

Subject to the Terms of Service and Privacy Policy contained in The Universe Codex.

The EGT Logo® and Intrepid™ marks are used under license.

© 2026 EGT. Built on The Universe Platform by EGT.