<?xml version="1.0" encoding="UTF-8"?>
<!-- Static sitemap: only deliberately-indexable public pages.
     Every URL here must return 200 (no redirect), be allowed by
     robots.txt, and carry a self-referencing canonical.
     The root / is intentionally NOT listed: it 301s to /login,
     which is the canonical public page.
     The robots.txt Allow list is a SUPERSET of this file and must not
     be mirrored into it. /terms and /cookies are deliberately allowed
     in robots.txt while serving noindex — they are crawlable so Google
     can read that noindex, but listing a noindex URL in a sitemap is
     itself a Search Console error. Crawlable != indexable.
     What must stay in sync is this file and the per-page robots meta
     policy (login.php, changelog.php, legal.php): every URL below
     serves "index, follow", and nothing that serves noindex belongs here.
     App, workspace, tenant, and token pages are intentionally absent.

     The trust pages are listed once PER LANGUAGE. Each language has its
     own URL (/privacy = English, /privacy/no = Norwegian) and its own
     self-referencing canonical; they previously shared one URL and were
     selected from the session, so a crawler only ever saw English.
     The reciprocal hreflang set lives in the page head, not here.
     /changelog is paginated but only page 1 is listed — the archive
     pages are reached through the numbered nav in its markup.
     terms and cookies have language URLs too, but stay noindex and so
     stay out of this file. -->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://hrcluster.app/login</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/changelog</loc>
  </url>

  <url>
    <loc>https://hrcluster.app/privacy</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/privacy/no</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/privacy/sv</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/privacy/da</loc>
  </url>

  <url>
    <loc>https://hrcluster.app/security</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/security/no</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/security/sv</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/security/da</loc>
  </url>

  <url>
    <loc>https://hrcluster.app/dpa</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/dpa/no</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/dpa/sv</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/dpa/da</loc>
  </url>

  <url>
    <loc>https://hrcluster.app/subprocessors</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/subprocessors/no</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/subprocessors/sv</loc>
  </url>
  <url>
    <loc>https://hrcluster.app/subprocessors/da</loc>
  </url>
</urlset>
