Visible pages: home, services, about, common questions. The price list, if it is published on the site. Terms, policies and contact details written in the open. In short - everything anyone sees without logging in.
The site's code - we don't go into it at all. The database and admin systems - we have no access. Passwords, personal areas, closed dashboards. Data about customers, patients or staff - we don't see it.
There is a difference between "we promised not to go in" and "we have no way in". Here it is the second. We reach the site the way any visitor does, from the outside. There is no connection to your systems that could be left on or misconfigured - there simply is no such connection. It is the boundary of how the work is built, not a box someone has to remember to tick.
How it updates without internal access When the site changes, the access re-reads the public content. Access to systems is not needed to update, because everything required is already public on the site.
Less sensitive data - less exposure Because we don't collect your customers' personal data, there is no pile of sensitive information sitting with a third party. That keeps the picture simpler against requirements like GDPR too.